Verifisert mot offisiell MS-doc (juni 2026): «Microsoft Foundry» er det gjeldende produkt-/portalnavnet; «Foundry (classic)» = gamle «Azure AI Foundry» (/azure/foundry/ vs /azure/foundry-classic/). Premiss bekreftet før sveip. Multi-regel, IKKE naiv s/Azure AI Foundry/Microsoft Foundry/ — MS dropper «Azure AI» (legger IKKE til «Microsoft») for to produktvarianter: - «Azure AI Foundry Agent[ Service|s]» → «Foundry Agent Service/Agents» (MS-form) - «Azure AI Foundry Models» → «Foundry Models» (i «Azure OpenAI in Foundry Models») - «Azure AI Foundry SDK» → «Microsoft Foundry SDK» (operatør-valg) - «Azure AI Foundry portal/project» + generisk → «Microsoft Foundry» - Pre-eksisterende «Microsoft Foundry Models» (4) normalisert → «Foundry Models» Bevart: «Azure OpenAI», «Azure AI Inference SDK», «Azure AI Search», «Azure AI Services», kode-IDer. Historisk ref «(tidligere Azure AI Foundry)» i model-catalog-2026.md beskyttet via lookbehind. URL /azure/ai-foundry/→ /azure/foundry/ kun i owasp-llm-top10 (KB-ref); docs/-filer deferred. Scope: skills (inkl. 3 SKILL.md) + commands + agents + README + CLAUDE. Ekskludert: docs/ (interne), playground/+tests/ fixtures (testdata), CHANGELOG.md (historisk logg), STATE.md (gitignored). 3 SKILL.md endret (advisor/engineering/security) → judge-cache teknisk invalidert for disse, men scorer uendret: advisor 91, eng/gov/infra/sec 96 (alle ≥90). validate 239/0. 0 «Azure AI Foundry» igjen (utenom bevart ref). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
924 lines
45 KiB
Markdown
924 lines
45 KiB
Markdown
# Enterprise Governance and Deployment Controls
|
||
|
||
**Last updated:** 2026-06-19
|
||
**Status:** GA
|
||
**Category:** Copilot Extensibility & Integration
|
||
|
||
---
|
||
|
||
## Introduksjon
|
||
|
||
Enterprise governance og deployment controls for Microsoft Copilot-plattformen omfatter et helhetlig rammeverk for å administrere livssyklus, tilgang, sikkerhet og samsvar på tvers av alle Copilot-utvidelser. Dette inkluderer Microsoft 365 Copilot agents, Copilot Studio-agenter, og integrerte AI-kapabiliteter i Power Platform.
|
||
|
||
Microsoft tilbyr tre fundamentale deployment-modeller med tilhørende governance-kontroller:
|
||
|
||
1. **Microsoft-installed agents** — Microsoft pre-installer og pre-pinner høyverdiagenter (Researcher, Analyst) for alle lisensierte brukere
|
||
2. **Admin-installed agents** — IT-administratorer installer custom-built, Microsoft-built eller partner-built agents med full livssykluskontroll
|
||
3. **User-installed agents** — Sluttbrukere installer agents fra Agent Store eller builder egne agents basert på tenant-policies
|
||
|
||
Alle deployment-modeller administreres gjennom **Copilot Control System (CCS)** i Microsoft 365 admin center, som gir sentralisert synlighet og granulære kontroller på tenant-, miljø- og agentnivå.
|
||
|
||
Governance-strategien må balansere **enablement** (empowerment av citizen developers og pro developers) med **control** (sikkerhet, compliance, risikostyring). Microsoft anbefaler en **zoned governance strategy** som segmenterer environments basert på risiko og kompleksitet.
|
||
|
||
**Verified** — Basert på offisiell Microsoft Learn-dokumentasjon (2026-02).
|
||
|
||
---
|
||
|
||
## Kjernekomponenter
|
||
|
||
### 1. Copilot Control System (CCS)
|
||
|
||
Sentralisert administrasjonspanel i Microsoft 365 admin center (`admin.microsoft.com > Copilot > Agents`).
|
||
|
||
**Microsoft Agent 365 (ny kontrollplan 2026):** Microsoft Agent 365 er den nye sentraliserte kontrollplanen for alle agenter på tvers av M365 og Copilot Studio. Den samler agent-inventar, livssyklusstyring og policy-enforcement for Microsoft-bygde og IT-installerte agenter på én plass. Erstatter gradvis scattered admin-kontroller på tvers av multiple portaler. Verified (MCP 2026-04).
|
||
|
||
**Kapabiliteter:**
|
||
- **Agent inventory** — Oversikt over alle agents i organisasjonen (Microsoft-built, admin-installed, user-installed)
|
||
- **Lifecycle management** — Install, block, remove, pin/unpin agents for spesifikke brukere eller grupper
|
||
- **Deployment policies** — Konfigurer hvem som kan installere og bruke agents
|
||
- **Pinning controls** — Pin agents til Copilot rail for synlighet og adoption
|
||
- **Orphaned agent detection** — Identifiser agents uten owner for cleanup
|
||
- **Agent Store-godkjenning (MCP 2026-06)** — Agenter fra Agent Store må gjennom innsending + admin-godkjenning via **Agent Registry** i M365 admin center; admins vurderer **agent-forespørsler** og publiserer/avviser. Publisering til organisasjonen støttes nå også i Government Community Cloud High (GCCH) og Moderate (GCCM)
|
||
|
||
**Begrensninger:**
|
||
- Microsoft-installed agents (Researcher, Analyst) kan kun blokkeres tenant-wide — granulære kontroller er grayed-out
|
||
- Admins kan kun slette shared agents og custom LOB agents (ikke Microsoft-built agents)
|
||
|
||
**Presisering (MCP 2026-06):** Researcher og Analyst er strengt tatt **ikke agenter**, men førsteparts Copilot-opplevelser i Microsoft 365 Copilot Chat (under **Tools**), bygget på samme fundament som M365 Copilot og innenfor M365 commercial data processing boundary. De sameksisterer med agenter og følger agent-relaterte governance-kapabiliteter, men styres **ikke** av agent-spesifikke innstillinger.
|
||
|
||
### 2. Zoned Governance Strategy
|
||
|
||
Microsoft anbefaler en tredelt governance-modell basert på risiko og teknisk kompleksitet:
|
||
|
||
| Zone | Beskrivelse | Builder Tools | Governance |
|
||
|------|-------------|---------------|------------|
|
||
| **Zone 1: Citizen Development** | Personlige og team-produktivitetsagenter. Read-only, private. Lav risiko. | Agent Builder (M365 Copilot), SharePoint agents | Developer environments med environment routing. Sharing disabled. |
|
||
| **Zone 2: Partnered Development** | IT-godkjente makers bygger agents for teams/avdelinger. Moderat risiko. | Copilot Studio | IT-managed environments, review-prosesser, ALM pipelines, scoped roles. |
|
||
| **Zone 3: Professional Development** | Mission-critical, enterprise-grade agents. Høy risiko. | Copilot Studio, Foundry Agent Service | Strengeste security controls, standard ALM, SLAs, audit trails. |
|
||
|
||
**Secure-kontroller per zone:**
|
||
- Zone 1: Kun Microsoft 365 og Power Platform connectors. Agents kjører i user context.
|
||
- Zone 2: Advanced connector policies, team access til godkjente datakilder, environment groups.
|
||
- Zone 3: Advanced connector policies + Microsoft Purview integration.
|
||
|
||
**Govern-kontroller per zone:**
|
||
- Zone 1: Developer environments med environment routing. Sharing disabled.
|
||
- Zone 2: Admin-approved provisioning, scoped roles, ALM pipelines, IT-admin approval for publishing.
|
||
- Zone 3: Integrated Apps management i M365 admin center. Gated release processes.
|
||
|
||
### 3. Power Platform Environment Controls
|
||
|
||
Copilot Studio-agenter lever alltid innenfor Power Platform environments, som fungerer som logical containers med egne:
|
||
- **Data boundaries** — Bestemmer hvor agent data lagres (geo-residency)
|
||
- **Security roles** — Dataverse security roles for CRUD-operasjoner på Copilot, Copilot Subcomponent, Conversation Transcript tables
|
||
- **Data policies** — DLP-policies for å blokkere/tillate connectors, channels, knowledge sources
|
||
- **Lifecycle separation** — Dev/test/prod isolation
|
||
|
||
**Environment routing** dirigerer makers til riktig environment basert på intent (eksperimentering vs produksjon).
|
||
|
||
### 4. Data Loss Prevention (DLP) Policies
|
||
|
||
Enforceres på tre nivåer:
|
||
|
||
| Nivå | DLP-kontroller |
|
||
|------|----------------|
|
||
| **Tenant** | Block/allow unauthenticated usage, channels, knowledge sources, connectors, skills, Application Insights integration. Block/allow publishing av GenAI-agents. |
|
||
| **Environment** | Scope policies til spesifikke environments. Block/allow public data sources (Bing). Block/allow GenAI features uten regional Azure OpenAI capacity. Network isolation (VNET, IP firewall). |
|
||
| **Agent** | Enable/disable generative orchestration, AI knowledge, generative answers, intelligent topic authoring. Set authentication (none, Microsoft, manual). Enforce web channel security. |
|
||
|
||
**PowerShell-eksempel for DLP policy:**
|
||
```powershell
|
||
# Create DLP policy for Copilot experiences
|
||
$loc = "[{\"Workload\":\"Applications\",\"Location\":\"470f2276-e011-4e9d-a6ec-20768be3a4b0\",\"Inclusions\":[{Type:\"Tenant\", Identity:\"All\"}]}]"
|
||
|
||
New-DLPCompliancePolicy -Name "Copilot Policy" -Locations $loc -EnforcementPlanes @("CopilotExperiences")
|
||
|
||
# Create rule blocking sensitive content
|
||
$advRule = @{
|
||
"Version" = "1.0"
|
||
"Condition" = @{
|
||
"Operator" = "And"
|
||
"SubConditions" = @(
|
||
@{
|
||
"ConditionName" = "ContentContainsSensitiveInformation"
|
||
"Value" = @(
|
||
@{
|
||
"groups" = @(
|
||
@{
|
||
"Operator" = "Or"
|
||
"labels" = @(
|
||
@{
|
||
"name" = $guidVar
|
||
"type" = "Sensitivity"
|
||
}
|
||
)
|
||
"name" = "Default"
|
||
}
|
||
)
|
||
}
|
||
)
|
||
}
|
||
)
|
||
}
|
||
} | ConvertTo-Json -Depth 100
|
||
|
||
New-DLPComplianceRule -Name "Copilot Rule" -Policy "Copilot Policy" -AdvancedRule $advrule -RestrictAccess @(@{setting="ExcludeContentProcessing";value="Block"})
|
||
```
|
||
|
||
### 5. Maker Access Controls
|
||
|
||
| Nivå | Access Controls |
|
||
|------|-----------------|
|
||
| **Tenant** | Assign Copilot Studio User license eller M365 Copilot license. Copilot Author settings for pay-as-you-go. Block/allow self-service trials. Block/allow Copilot Studio Teams app. |
|
||
| **Environment** | Block/allow environment access via security groups. Security roles for CRUD operations på agents. |
|
||
| **Agent** | Share/unshare agents for collaborative authoring. System Administrator role kan read/update alle agents og transcripts. |
|
||
|
||
### 6. Application Lifecycle Management (ALM)
|
||
|
||
**For Zone 2 og Zone 3:**
|
||
- **Pipelines** — Automatiserte deployment pipelines fra dev → test → prod
|
||
- **Versioning** — Structured versioning med rollback-kapabiliteter
|
||
- **Gated releases** — Review-prosesser før produksjonsdeploy
|
||
- **Solution packaging** — Agents pakkes som Power Platform solutions for transport
|
||
|
||
**ALM-verktøy:**
|
||
- Power Platform ALM pipelines
|
||
- Azure DevOps integration
|
||
- GitHub Actions support (via Power Platform Build Tools)
|
||
|
||
### 7. Reporting and Monitoring
|
||
|
||
**Microsoft 365 admin center:**
|
||
- Copilot readiness reports (license eligibility, adoption metrics)
|
||
- Usage analytics (Copilot Dashboard i Viva Insights)
|
||
- Agent inventory og orphaned agent detection
|
||
|
||
**Microsoft Purview:**
|
||
- Audit logs for all Copilot activities (compliance tracking)
|
||
- Sensitivity label enforcement
|
||
- Data governance posture
|
||
|
||
**Power Platform admin center:**
|
||
- Agent usage og security posture
|
||
- Environment health monitoring
|
||
- Connector usage analytics
|
||
- Capacity consumption metrics
|
||
|
||
### 8. Advanced Security Controls
|
||
|
||
**Customer-Managed Keys (CMK):**
|
||
- Encrypt agent data at rest med customer's own key
|
||
- Cyclic key rotation support
|
||
- Kan aktiveres/deaktiveres per environment
|
||
|
||
**Network isolation:**
|
||
- Virtual Network (VNET) support for Copilot Studio environments
|
||
- IP firewall rules for inbound/outbound traffic
|
||
- Private endpoints for secure connectivity
|
||
|
||
**Authentication og authorization:**
|
||
- Agent authentication: None, Microsoft, Manual (custom OAuth)
|
||
- Role-based access control (RBAC) via Dataverse security roles
|
||
- Microsoft Entra ID group-based security
|
||
- **Single-tenant Entra ID app registration for nye agenter (Verified 2026-05):** Copilot Studio oppretter én app-registrering per custom agent for å identifisere og sikre kommunikasjon med kanaler/skills. Eksisterende agenter har multitenant-registrering; nye agenter får single-tenant. Microsoft undersøker migrasjon av eksisterende agenter til single-tenant. App-registreringen aksesserer ikke kundedata.
|
||
- **Tenant isolation:** Ikke støttet by default i Copilot Studio. Cross-tenant connections er tillatt med Entra ID-credentials. Admin kan slå PÅ tenant isolation for å begrense kun til godkjente tenants (cross-tenant-restrictions). (Verified 2026-05)
|
||
|
||
---
|
||
|
||
## Arkitekturmønstre
|
||
|
||
### Pattern 1: Centralized Governance with Federated Execution
|
||
|
||
**Scenario:** Global enterprise med flere divisjoner som skal bygge egne Copilot-agenter, men med sentralisert IT-oversikt.
|
||
|
||
**Arkitektur:**
|
||
```
|
||
Tenant-level
|
||
├── Copilot Control System (CCS) — Sentralisert agent inventory og policies
|
||
├── Global DLP policies — Blokkerer sensitive connectors (Zone 1)
|
||
└── Maker welcome message — Privacy og compliance requirements
|
||
|
||
Division A (Zone 2)
|
||
├── Dedicated environment (Dev, Test, Prod)
|
||
├── Scoped DLP policies — Tillater godkjente connectors
|
||
├── Security groups — Division A makers + IT coaches
|
||
└── ALM pipeline — Automated dev → test → prod
|
||
|
||
Division B (Zone 2)
|
||
├── Dedicated environment (Dev, Test, Prod)
|
||
├── Scoped DLP policies — Tillater godkjente connectors
|
||
├── Security groups — Division B makers + IT coaches
|
||
└── ALM pipeline — Automated dev → test → prod
|
||
|
||
IT Pro (Zone 3)
|
||
├── Enterprise environment (Dev, Test, Prod)
|
||
├── Strengeste DLP policies + Microsoft Purview
|
||
├── Pro developer access only
|
||
└── Full ALM med code review gates
|
||
```
|
||
|
||
**Governance-flyt:**
|
||
1. Makers i Zone 2 bygger agents i dev environment
|
||
2. IT coach reviewer agent før test deployment
|
||
3. ALM pipeline flytter agent til test environment
|
||
4. IT admin godkjenner prod deployment via CCS
|
||
5. Agent pinnes til relevante brukere via M365 admin center
|
||
|
||
### Pattern 2: Progressive Rollout with Pilot Groups
|
||
|
||
**Scenario:** Organisasjon som vil teste Copilot-agents med en pilot-gruppe før enterprise-wide deployment.
|
||
|
||
**Deployment-faser:**
|
||
```
|
||
Phase 1: Pilot (50 users)
|
||
├── Admin-installed agent via CCS
|
||
├── Deploy til pilot security group
|
||
├── Pin agent i Copilot rail for synlighet
|
||
└── Monitor usage via Viva Insights Copilot Dashboard
|
||
|
||
Phase 2: Expanded Pilot (500 users)
|
||
├── Deploy til flere security groups
|
||
├── Samle feedback og iterér på agent
|
||
└── Mål KPIs (adoption rate, satisfaction score)
|
||
|
||
Phase 3: Enterprise Deployment (All users)
|
||
├── Deploy tenant-wide via CCS
|
||
├── Pin agent for alle brukere
|
||
├── Enable self-service via Agent Store
|
||
└── Continuous monitoring via Purview audit logs
|
||
```
|
||
|
||
**Governance-kontroller:**
|
||
- Phase 1-2: DLP policy blokkerer external connectors
|
||
- Phase 3: DLP policy tillater godkjente external connectors
|
||
- Alle faser: Microsoft Purview sensitivity labels enforced
|
||
|
||
### Pattern 3: Hybrid Agent Distribution (M365 Copilot + Copilot Studio)
|
||
|
||
**Scenario:** Organisasjon som bruker både Agent Builder (M365 Copilot) for enkle agents og Copilot Studio for avanserte agents.
|
||
|
||
**Arkitektur:**
|
||
```
|
||
Zone 1 (Citizen Development)
|
||
├── Agent Builder i M365 Copilot
|
||
├── SharePoint agents (site-scoped knowledge)
|
||
├── Developer environments (auto-provisioned)
|
||
└── Sharing disabled — kun personal use
|
||
|
||
Zone 2 (Partnered Development)
|
||
├── Copilot Studio agents
|
||
├── IT-managed environments
|
||
├── Advanced capabilities: Custom connectors, API calls, workflows
|
||
└── Publishing krever IT-admin approval
|
||
|
||
Governance-bro:
|
||
├── Copy Agent Builder agent → Copilot Studio for advanced features
|
||
├── CCS tracking av alle agents uavhengig av builder tool
|
||
└── Unified reporting via M365 admin center + Power Platform admin center
|
||
```
|
||
|
||
**Migration-flyt (Agent Builder → Copilot Studio):**
|
||
1. User bygger agent i Agent Builder (Zone 1)
|
||
2. User initierer "Copy to Copilot Studio" via UI
|
||
3. Agent kopieres til IT-managed environment (Zone 2)
|
||
4. IT team legger til advanced features (connectors, workflows)
|
||
5. IT admin publiserer til Teams app catalog
|
||
6. Agent pinnes organisation-wide via CCS
|
||
|
||
### Pattern 4: Multi-Geo Deployment with Data Residency
|
||
|
||
**Scenario:** Organisasjon med data residency-krav (f.eks. offentlig sektor Norge).
|
||
|
||
**Arkitektur:**
|
||
```
|
||
Norway Region
|
||
├── Power Platform environment (Norway data region)
|
||
├── Copilot Studio agents (data lagres i Norway)
|
||
├── Azure OpenAI Service (Norway North eller Sweden Central)
|
||
└── DLP policy: Block data movement utenfor region
|
||
|
||
US Region
|
||
├── Power Platform environment (US data region)
|
||
├── Copilot Studio agents (data lagres i US)
|
||
├── Azure OpenAI Service (US region)
|
||
└── DLP policy: Block data movement utenfor region
|
||
|
||
Tenant-level
|
||
├── CCS: Agent inventory for alle regioner
|
||
├── Global DLP baseline policies
|
||
└── Regional DLP policies (inherit + override)
|
||
```
|
||
|
||
**Governance-kontroller:**
|
||
- Environment-level setting: Block GenAI features som krever data movement outside region
|
||
- Power Platform environment groups: Auto-routing av makers til riktig regional environment
|
||
- Microsoft Purview: Geo-fencing policies for sensitive content
|
||
|
||
---
|
||
|
||
## Beslutningsveiledning
|
||
|
||
### Når bruke ulike deployment-modeller?
|
||
|
||
| Deployment-modell | Use Case | Governance Overhead |
|
||
|-------------------|----------|---------------------|
|
||
| **Microsoft-installed agents** | Høyverdi general-purpose agents (Researcher, Analyst). | Lav — kun tenant-wide block/allow. |
|
||
| **Admin-installed agents** | Custom LOB agents for spesifikke teams/divisjoner. | Medium — full lifecycle management, men ikke kode-vedlikehold. |
|
||
| **User-installed agents** | Personal productivity agents, eksperimentering. | Lav — tenant policy enforcement, self-service. |
|
||
|
||
### Når bruke Copilot Control System vs Power Platform admin center?
|
||
|
||
| Admin Portal | Use Case |
|
||
|--------------|----------|
|
||
| **M365 admin center (CCS)** | Lifecycle management av M365 Copilot agents (install, block, remove, pin). Agent inventory. Deployment policies. |
|
||
| **Power Platform admin center** | Environment management, DLP policies, connector governance, ALM pipelines, capacity monitoring. |
|
||
| **Purview portal** | Audit logs, sensitivity labels, retention policies, compliance reporting. |
|
||
|
||
**Regel:** Bruk CCS for agent-fokusert governance, Power Platform admin center for environment-fokusert governance, Purview for compliance.
|
||
|
||
### Når bruke Zone 1 vs Zone 2 vs Zone 3?
|
||
|
||
| Kriterier | Zone 1 | Zone 2 | Zone 3 |
|
||
|-----------|--------|--------|--------|
|
||
| **Målgruppe** | Single user, team | Department, multiple teams | Enterprise-wide |
|
||
| **Risk level** | Lav (read-only, personal data) | Moderat (team data, approved connectors) | Høy (mission-critical, external integrations) |
|
||
| **Technical complexity** | Enkel (no-code, predefined knowledge) | Moderat (low-code, custom connectors) | Høy (pro-code, complex workflows, ALM) |
|
||
| **Approval process** | Ingen (self-service) | IT coach review | IT admin approval + ALM gates |
|
||
| **SLA requirements** | Ingen | Best-effort | Formal SLA |
|
||
| **Sharing scope** | Private eller team-wide | Department-wide | Organisation-wide |
|
||
|
||
**Decision tree:**
|
||
```
|
||
Start
|
||
├── "Skal agenten aksesse sensitive systemer?" → Ja → Zone 3
|
||
├── "Skal agenten deles på tvers av teams?" → Ja → Zone 2 eller 3
|
||
├── "Krever agenten custom connectors eller workflows?" → Ja → Zone 2 eller 3
|
||
└── Ellers → Zone 1
|
||
```
|
||
|
||
### Når bruke Agent Builder (M365 Copilot) vs Copilot Studio?
|
||
|
||
| Kriterier | Agent Builder | Copilot Studio |
|
||
|-----------|---------------|----------------|
|
||
| **Builder persona** | Business user, citizen developer | IT-approved maker, pro developer |
|
||
| **Knowledge sources** | SharePoint sites, uploaded files | SharePoint, Dataverse, custom connectors, APIs |
|
||
| **Workflow complexity** | Ingen workflows | Complex workflows med conditional logic |
|
||
| **Integration** | Microsoft 365 apps only | Microsoft 365, Teams, websites, custom endpoints |
|
||
| **ALM support** | Ingen | Full ALM (dev/test/prod, versioning, pipelines) |
|
||
| **Governance overhead** | Lav | Høy |
|
||
| **Licensing** | M365 Copilot license | Copilot Studio license eller M365 Copilot license |
|
||
|
||
**Migrasjonssti:** Start i Agent Builder for MVP, copy to Copilot Studio når du trenger advanced features.
|
||
|
||
### Når bruke environment routing?
|
||
|
||
**Use Case:** Sikre at makers alltid lander i riktig environment basert på intent.
|
||
|
||
**Konfigurasjon:**
|
||
- Default environment: Zone 1 (citizen development, personal use)
|
||
- Scoped environments: Zone 2/3 (IT-managed, team/department/enterprise)
|
||
|
||
**Rules:**
|
||
- User er ikke medlem av noen security group → Route til default environment (Zone 1)
|
||
- User er medlem av "Division A Makers" security group → Route til Division A environment (Zone 2)
|
||
- User er medlem av "IT Pro Developers" security group → Route til Enterprise environment (Zone 3)
|
||
|
||
**Fordel:** Forhindrer at makers utilsiktet bygger agents i feil environment (f.eks. prod environment).
|
||
|
||
---
|
||
|
||
## Integrasjon med Microsoft-stakken
|
||
|
||
### Microsoft 365 Copilot
|
||
|
||
**Agent installation metoder:**
|
||
1. **Prepinned agents** — Microsoft pre-pinner Researcher og Analyst agents i Copilot rail
|
||
2. **Admin-pinned agents** — IT pinner custom agents via CCS for spesifikke brukere/grupper
|
||
3. **User-installed agents** — Users installerer fra Agent Store basert på tenant policies
|
||
4. **Frontier agents (ny 2026):** Microsoft-bygde spesialiserte agenter med utvidede kapabiliteter — inkluderer **App Builder** (hjelper brukere bygge Power Apps/Copilot Studio-agenter via dialog) og **Workflows** (automatiserer prosesser via voice/text til Power Automate). Distribusjon og governance via standard CCS-kontroller. Verified (MCP 2026-04).
|
||
|
||
**Governance integration:**
|
||
- CCS for agent lifecycle management
|
||
- Microsoft Entra ID for authentication og security groups
|
||
- Microsoft Teams admin center for pinning Copilot app i Teams
|
||
|
||
**Settings management:**
|
||
- Cloud Policy for **Copilot Pages og Copilot Notebooks** creation (admin-konfigurasjon via CPCN-admin settings, se cpcn-admin-configuration). Verified (MCP 2026-04).
|
||
- Feature access management for Copilot i Viva apps (Glint, Insights)
|
||
- Data access policies (web search, organizational data, People Skills)
|
||
|
||
### Copilot Studio
|
||
|
||
**Environment dependencies:**
|
||
- Alle Copilot Studio agents lever innenfor Power Platform environments
|
||
- Environment bestemmer data residency, security roles, DLP policies
|
||
- Environment routing dirigerer makers til riktig environment
|
||
|
||
**Governance integration:**
|
||
- Power Platform admin center for environment management
|
||
- Dataverse for agent metadata storage (Copilot, Copilot Subcomponent, Conversation Transcript tables)
|
||
- ALM pipelines for agent deployment
|
||
|
||
**Publishing workflows:**
|
||
- Zone 2/3: Publishing krever IT-admin approval via Power Platform admin center
|
||
- Publishing til Teams app catalog krever Microsoft Teams admin approval
|
||
- Organisation-wide pinning via CCS etter publishing
|
||
|
||
### Microsoft Purview
|
||
|
||
**Data protection:**
|
||
- Sensitivity labels enforced på agent responses (kun inkluder data user har access til)
|
||
- DLP policies for å blokkere agents med sensitive content
|
||
- Audit logs for all Copilot activities (interactions, agent deployments, policy changes)
|
||
|
||
**Compliance:**
|
||
- **DSPM for AI som "front door"** — Data Security Posture Management for AI er nå anbefalt startpunkt for å oppdage, sikre og anvende compliance-kontroller på tvers av AI-bruk i tenantet (Verified 2026-05)
|
||
- **Tre AI-app-kategorier i Purview:**
|
||
1. **Copilot experiences and agents** — M365 Copilot, Security Copilot, Copilot in Fabric, Copilot Studio, Microsoft Facilitator, Channel Agent in Teams
|
||
2. **Enterprise AI apps** — Entra-registered AI apps, Microsoft Foundry, ChatGPT Enterprise, **Anthropic Claude (Enterprise)** (lagt til MCP 2026-06)
|
||
3. **Other AI apps** — Tredjepart-LLMs (ChatGPT consumer, Google Gemini, DeepSeek) detektert via Defender for Cloud Apps
|
||
- **Microsoft Agent 365** har dedikert Purview-side (`ai-agent-365`) for security & compliance
|
||
- **Risky AI usage policy template** i Insider Risk Management — detekterer prompt injection-angrep og tilgang til beskyttet materiale, integrert med Microsoft Defender XDR (Verified 2026-05)
|
||
- Communication compliance (monitor agent responses for compliance violations)
|
||
- eDiscovery (search agent conversation transcripts for legal holds — bruk `Copilot activity` query condition)
|
||
- Retention policies (auto-delete agent conversations etter retention period)
|
||
|
||
**PowerShell-eksempel for Purview collection policy:**
|
||
```powershell
|
||
# Create collection policy for Copilot
|
||
New-FeatureConfiguration -Name "Collection policy for supported Copilots" `
|
||
-FeatureScenario KnowYourData `
|
||
-Mode Enable `
|
||
-ScenarioConfig '{
|
||
"Activities":["UploadText","DownloadText"],
|
||
"EnforcementPlanes":["CopilotExperiences","Browser"],
|
||
"SensitiveTypeIds":["All"],
|
||
"IsIngestionEnabled":true
|
||
}' `
|
||
-Locations '[{
|
||
"Workload":"Applications",
|
||
"Location":"52655",
|
||
"Inclusions":[{"Type":"Tenant","Identity":"All"}]
|
||
}]'
|
||
```
|
||
|
||
### Power Platform
|
||
|
||
**Connector governance:**
|
||
- DLP policies for å blokkere/tillate connectors på tenant/environment/agent nivå
|
||
- Advanced connector policies for granular control (f.eks. tillat Dataverse men blokker external APIs)
|
||
- Connector usage analytics i Power Platform admin center
|
||
|
||
**Environment groups:**
|
||
- Grupper environments basert på purpose (dev, test, prod) eller division
|
||
- Apply common policies til alle environments i en group
|
||
- Skalerer governance på tvers av mange environments
|
||
|
||
**Pay-as-you-go:**
|
||
- Copilot Author settings for å aktivere pay-as-you-go licensing
|
||
- Maker access controls for å begrense hvem som kan bruke pay-as-you-go
|
||
|
||
### Microsoft Teams
|
||
|
||
**Agent distribution:**
|
||
- Copilot Studio agents kan publiseres til Teams app catalog
|
||
- Teams admin må approve agent før organisation-wide tilgjengelighet
|
||
- App setup policies for å pinne agents i Teams
|
||
|
||
**Copilot i Teams:**
|
||
- Teams meeting policies for Copilot (enabled, disabled, enabled with transcript)
|
||
- Teams calling policies for Copilot (enabled, disabled, enabled with transcript)
|
||
- PowerShell-kontroll via `Set-CsTeamsMeetingPolicy` og `Set-CsTeamsCallingPolicy`
|
||
|
||
**PowerShell-eksempel:**
|
||
```powershell
|
||
# Enable Copilot for Teams meetings
|
||
Set-CsTeamsMeetingPolicy -Identity <policy name> -Copilot Enabled
|
||
|
||
# Enable Copilot for Teams calls with transcript
|
||
Set-CsTeamsCallingPolicy -Identity <policy name> -Copilot EnabledWithTranscript -AllowTranscriptionForCalling $true
|
||
```
|
||
|
||
### SharePoint
|
||
|
||
**SharePoint agents:**
|
||
- Site-scoped agents basert på SharePoint site content
|
||
- Builder: SharePoint site owners
|
||
- Governance: SharePoint Advanced Management (SAM) for content governance
|
||
- Oversharing prevention: SharePoint sharing settings, site ownership cleanup, unused site deletion
|
||
|
||
**Microsoft 365 Copilot data governance:**
|
||
- Copilot respekterer SharePoint permissions (kun inkluder content user har access til)
|
||
- Oversharing blueprint: Pilot → Deploy → Operate phases med SAM og Purview
|
||
|
||
### Microsoft Foundry
|
||
|
||
**Integration point:**
|
||
- Zone 3 (Professional Development) kan bruke Foundry Agent Service for mission-critical agents
|
||
- Agents deployes som Azure-tjenester med full Azure governance (RBAC, networking, monitoring)
|
||
- Integration med Copilot Studio via custom connectors (agent-to-agent orchestration)
|
||
|
||
**Governance-fordel:**
|
||
- Full control over agent infrastructure (compute, storage, networking)
|
||
- Azure Policy enforcement for compliance
|
||
- Azure Monitor og Application Insights for observability
|
||
|
||
---
|
||
|
||
## Offentlig sektor (Norge)
|
||
|
||
### Data residency og GDPR
|
||
|
||
**Power Platform environments:**
|
||
- Opprett environments med Norway data region for data residency compliance
|
||
- Azure OpenAI Service: Norway North (eller Sweden Central fallback)
|
||
- Verifiser at ingen data movement skjer utenfor Europa
|
||
|
||
**DLP policies:**
|
||
- Environment-level setting: "Block GenAI features som krever data movement outside region"
|
||
- Blokkerer features som ikke har regional Azure OpenAI capacity
|
||
|
||
**Microsoft Purview:**
|
||
- Sensitivity labels for "Begrenset" og "Konfidensielt" content
|
||
- Geo-fencing policies: Auto-blokkér deling av sensitive labels utenfor Norway/EU
|
||
- Audit logs for GDPR Article 30 compliance (processing activities record)
|
||
|
||
### Schrems II compliance
|
||
|
||
**Data residency requirements:**
|
||
- Alle Copilot Studio agent data lagres i Norge (eller EU)
|
||
- Azure OpenAI API calls går til Norway North (ikke US)
|
||
- Conversation transcripts lagres i Dataverse (Norway region)
|
||
|
||
**Data Processing Agreement (DPA):**
|
||
- Microsoft Product Terms inkluderer DPA for Copilot Studio og M365 Copilot
|
||
- DPA covers data residency, subprocessors, audit rights
|
||
|
||
**Recommended architecture:**
|
||
```
|
||
Norway Data Region
|
||
├── Power Platform environment (Norway)
|
||
├── Dataverse (Norway) — Agent metadata og transcripts
|
||
├── Azure OpenAI Service (Norway North)
|
||
├── SharePoint (EU) — Knowledge sources
|
||
└── Microsoft Purview (EU) — Audit logs
|
||
|
||
DLP Policy: Block data movement outside EU
|
||
```
|
||
|
||
### Etat-spesifikke krav
|
||
|
||
**Common patterns i norsk offentlig sektor:**
|
||
|
||
1. **Sensitive datahåndtering:**
|
||
- Sensitivity labels: "Begrenset", "Konfidensielt", "Strengt fortrolig"
|
||
- DLP policies: Auto-blokkér agents som aksesser "Strengt fortrolig" content
|
||
- Customer-Managed Keys (CMK) for data-at-rest encryption
|
||
|
||
2. **Four-eyes principle:**
|
||
- Zone 2/3: Krever IT coach review før test deployment
|
||
- Zone 3: Krever IT admin approval + ALM gates før prod deployment
|
||
- Audit logs for all approvals (traceable i Purview)
|
||
|
||
3. **Separation of duties:**
|
||
- Security groups: Makers vs Reviewers vs Admins
|
||
- RBAC: Maker har kun "Copilot Author" role, ikke "System Administrator"
|
||
- Environment isolation: Separate environments per etat/avdeling
|
||
|
||
4. **Auditability:**
|
||
- Microsoft Purview audit logs for all Copilot interactions
|
||
- Retention policies: 7 år for audit logs (Arkivverkets krav)
|
||
- eDiscovery-readiness for internal investigations
|
||
|
||
### Pilot-pattern for offentlig sektor
|
||
|
||
**Phase 1: Proof of Concept (4-8 uker)**
|
||
- Opprett pilot-environment (Norway region) i Zone 1
|
||
- 5-10 pilot users bygger personlige agents (Agent Builder)
|
||
- Evaluate: Data residency, GDPR compliance, user experience
|
||
|
||
**Phase 2: Controlled Pilot (2-3 måneder)**
|
||
- Opprett Zone 2 environment (Norway region)
|
||
- 50-100 pilot users bygger team agents (Copilot Studio)
|
||
- Implement: DLP policies, sensitivity labels, audit logging
|
||
- Evaluate: Oversharing risks, maker governance, IT overhead
|
||
|
||
**Phase 3: Departmental Rollout (3-6 måneder)**
|
||
- Deploy Zone 2 agents til 500-1000 users
|
||
- Implement: ALM pipelines, environment groups, reporting dashboards
|
||
- Iterate: DLP policies basert på feedback
|
||
|
||
**Phase 4: Enterprise Rollout (6-12 måneder)**
|
||
- Deploy tenant-wide via CCS
|
||
- Implement: Zone 3 for mission-critical agents
|
||
- Continuous monitoring via Purview og Power Platform admin center
|
||
|
||
**Governance-checkpoints:**
|
||
- Phase 1: GDPR compliance verification
|
||
- Phase 2: Security review (penetration testing, vulnerability assessment)
|
||
- Phase 3: Scalability review (capacity planning, cost optimization)
|
||
- Phase 4: Compliance audit (GDPR, Schrems II, Arkivloven)
|
||
|
||
---
|
||
|
||
## Kostnad og lisensiering
|
||
|
||
### Microsoft 365 Copilot Agents
|
||
|
||
**Licensing:**
|
||
- **Microsoft 365 Copilot license** — Inkluderer Agent Builder, user-installed agents, admin-installed agents
|
||
- **Ingen ekstra kostnad** for agent usage innenfor M365 Copilot
|
||
|
||
**Grenser:**
|
||
- Admin kan installere "limited number of agents" til Copilot rail (nøyaktig grense ikke publisert)
|
||
- User kan installere ubegrenset antall agents fra Agent Store (subject to tenant policies)
|
||
|
||
### Copilot Studio Agents
|
||
|
||
**Licensing-modeller:**
|
||
|
||
1. **Copilot Studio User license (standalone):**
|
||
- 250 NOK/user/måned (estimat basert på US pricing $200/måned)
|
||
- Inkluderer: Unlimited agent authoring, 25 000 AI Builder credits/måned
|
||
- Use case: Dedicated makers som bygger mange agents
|
||
|
||
2. **Microsoft 365 Copilot license (inkluderer Copilot Studio):**
|
||
- 415 NOK/user/måned (estimat basert på US pricing $30/måned)
|
||
- Inkluderer: Copilot Studio authoring, begrenset AI Builder credits
|
||
- Use case: Business users som både bruker M365 Copilot og bygger enkle agents
|
||
|
||
3. **Pay-as-you-go (consumption-based):**
|
||
- Ingen user license required
|
||
- Pay per agent interaction (messages) og AI Builder credits
|
||
- Use case: Low-volume agents, pilot scenarios
|
||
|
||
**Storage costs:**
|
||
- **Dataverse storage** — 15-20 NOK/GB/måned (estimat basert på US pricing $10/GB/måned)
|
||
- Agent metadata, conversation transcripts lagres i Dataverse
|
||
- Storage teller mot organisasjonens total Dataverse quota
|
||
- **Copilot Pages/Notebooks storage** — Teller mot SharePoint quota (included i M365 license)
|
||
|
||
**Azure OpenAI costs (for Copilot Studio GenAI features):**
|
||
- **Embedded i license** for standard GenAI features (generative answers, AI knowledge)
|
||
- **Additional charges** hvis agent kaller Azure OpenAI direkte via custom connector
|
||
- GPT-4o: 0.30 NOK/1K tokens input, 1.20 NOK/1K tokens output (estimat)
|
||
- Text Embedding 3 Small: 0.003 NOK/1K tokens (estimat)
|
||
|
||
### Governance-verktøy kostnad
|
||
|
||
| Verktøy | Lisens | Kostnad (estimat) |
|
||
|---------|--------|-------------------|
|
||
| **Microsoft 365 admin center (CCS)** | Included i M365 Copilot license | 0 NOK |
|
||
| **Power Platform admin center** | Included i Power Platform/Copilot Studio license | 0 NOK |
|
||
| **Microsoft Purview (audit logs, sensitivity labels)** | E5 license eller Purview standalone | 325 NOK/user/måned (E5) eller 125 NOK/user/måned (Purview) |
|
||
| **SharePoint Advanced Management (SAM)** | SAM license | 40 NOK/user/måned |
|
||
| **Viva Insights (Copilot Dashboard)** | Viva Insights license | 85 NOK/user/måned |
|
||
|
||
### Cost optimization strategies
|
||
|
||
**For small-scale deployments (< 100 users):**
|
||
- Bruk M365 Copilot license (inkluderer Copilot Studio) fremfor standalone Copilot Studio license
|
||
- Unngå pay-as-you-go (dyrere per interaction)
|
||
- Bruk Agent Builder (M365 Copilot) for enkle agents (ingen Dataverse storage cost)
|
||
|
||
**For large-scale deployments (> 1000 users):**
|
||
- Bruk standalone Copilot Studio license for dedicated makers
|
||
- Pay-as-you-go for low-volume agents (kun makers som trenger det)
|
||
- Environment groups for å dele resources på tvers av teams (reduce environment proliferation)
|
||
|
||
**Storage optimization:**
|
||
- **Retention policies** — Auto-delete gamle conversation transcripts etter 90 dager
|
||
- **Agent cleanup** — Slett unused agents og orphaned agents månedlig
|
||
- **Dataverse capacity monitoring** — Overvåk storage usage via Power Platform admin center
|
||
|
||
**AI Builder credits optimization:**
|
||
- Standard GenAI features (generative answers, AI knowledge) forbruker ikke AI Builder credits
|
||
- Custom AI models (document processing, prediction) forbruker credits
|
||
- Monitor credit usage via Power Platform admin center, kjøp add-on credits ved behov
|
||
|
||
### TCO-eksempel: 1000 users
|
||
|
||
**Scenario:** 1000 knowledge workers, 50 makers, 20 Copilot Studio agents (10 Zone 2, 10 Zone 3).
|
||
|
||
**Licensing:**
|
||
- 1000 users × 415 NOK/måned (M365 Copilot) = 415 000 NOK/måned
|
||
- Inkluderer: Agent Builder, agent usage, basic Copilot Studio authoring
|
||
|
||
**Governance (valgfritt):**
|
||
- 1000 users × 40 NOK/måned (SharePoint Advanced Management) = 40 000 NOK/måned
|
||
- 1000 users × 85 NOK/måned (Viva Insights for Copilot Dashboard) = 85 000 NOK/måned
|
||
- Alternative: E5 license (inkluderer SAM + Viva Insights + Purview) = 1000 × 650 NOK/måned = 650 000 NOK/måned
|
||
|
||
**Storage (estimat):**
|
||
- 20 agents × 5 GB Dataverse/agent = 100 GB × 20 NOK/GB/måned = 2 000 NOK/måned
|
||
|
||
**Total TCO (med governance):**
|
||
- **Lisenser:** 415 000 NOK/måned
|
||
- **Governance:** 125 000 NOK/måned (SAM + Viva Insights, ikke full E5)
|
||
- **Storage:** 2 000 NOK/måned
|
||
- **Total:** 542 000 NOK/måned = **6,5 MNOK/år**
|
||
|
||
**Confidence:** Medium — Basert på US pricing og estimert valutakurs. Verifiser med Microsoft partner for nøyaktige norske priser.
|
||
|
||
---
|
||
|
||
## For arkitekten (Cosmo)
|
||
|
||
### Key insights for Cosmo
|
||
|
||
1. **Governance er ikke bare policy enforcement — det er enablement:**
|
||
- Zoned governance strategy gir citizen developers frihet i Zone 1 mens IT beholder kontroll i Zone 2/3
|
||
- Environment routing sikrer at makers alltid lander i riktig plass uten friction
|
||
- Agent Builder → Copilot Studio migration path gir gradual complexity adoption
|
||
|
||
2. **Microsoft har bygget governance INTO platforms, ikke på toppen:**
|
||
- CCS er ikke en separat admin portal, men integrert i M365 admin center
|
||
- DLP policies er native Power Platform features, ikke third-party tools
|
||
- Microsoft Purview gir unified governance på tvers av M365 og Power Platform
|
||
|
||
3. **Data residency er first-class citizen i arkitekturen:**
|
||
- Power Platform environments har explicit data region setting
|
||
- DLP policies kan blokkere GenAI features som krever data movement outside region
|
||
- Dette er kritisk for offentlig sektor Norge (Schrems II compliance)
|
||
|
||
4. **Agent lifecycle management er modent og production-ready:**
|
||
- ALM pipelines, versioning, rollback er built-in i Power Platform
|
||
- Gated releases med approval workflows er standard practice
|
||
- Orphaned agent detection og cleanup er automatisert i CCS
|
||
|
||
5. **Governance overhead varierer drastisk per zone:**
|
||
- Zone 1: Minimal overhead (environment routing + tenant DLP policies)
|
||
- Zone 2: Moderat overhead (ALM pipelines + environment-level policies + IT coach review)
|
||
- Zone 3: Høy overhead (full ALM + pro developer access + SLAs + audit trails)
|
||
|
||
### Common pitfalls og hvordan unngå dem
|
||
|
||
**Pitfall 1: "Vi skal ha strict governance for alt"**
|
||
- **Problem:** Citizen developers kan ikke eksperimentere, innovation stopper
|
||
- **Solution:** Zoned governance — lav governance i Zone 1, høy governance i Zone 3
|
||
|
||
**Pitfall 2: "Vi skal bygge custom governance verktøy"**
|
||
- **Problem:** Reinventing the wheel, maintenance overhead, feature lag
|
||
- **Solution:** Bruk native Microsoft governance tools (CCS, Power Platform admin center, Purview)
|
||
|
||
**Pitfall 3: "Vi trenger ikke ALM for low-code agents"**
|
||
- **Problem:** Agents går direkte fra dev til prod uten testing, breaking changes rammes brukere
|
||
- **Solution:** ALM pipelines også for Zone 2 (ikke bare Zone 3)
|
||
|
||
**Pitfall 4: "Vi skal ha én environment for alt"**
|
||
- **Problem:** Ingen dev/test/prod separation, oversharing risk, makers bygger i prod
|
||
- **Solution:** Environment groups per division/team med dev/test/prod lifecycle
|
||
|
||
**Pitfall 5: "Governance kan vi fikse later"**
|
||
- **Problem:** Technical debt, retrofitting governance er vanskeligere enn upfront design
|
||
- **Solution:** Pilot with governance fra dag 1 — test governance i liten skala før scale-out
|
||
|
||
### Architecture decision prompts for Cosmo
|
||
|
||
**Når kunde sier "Vi vil ha Copilot agents", spør:**
|
||
1. "Hvilke zones trenger dere? Skal alle bygge agents (Zone 1) eller kun IT-godkjente makers (Zone 2/3)?"
|
||
2. "Har dere data residency-krav? (Norge/EU only, eller OK med global?)"
|
||
3. "Har dere eksisterende Power Platform footprint? (Kan gjenbruke environments/policies)"
|
||
4. "Trenger dere custom connectors eller workflows? (Bestemmer Agent Builder vs Copilot Studio)"
|
||
5. "Hva er risikoprofilen? (Mission-critical → Zone 3, team productivity → Zone 2, personal → Zone 1)"
|
||
|
||
**Når kunde sier "Hvordan administrerer vi agents?", spør:**
|
||
1. "Hvem skal administrere agents? (IT only, eller federated til division admins?)"
|
||
2. "Skal agents deles organisation-wide eller kun innenfor teams/divisioner?"
|
||
3. "Trenger dere pinning for å drive adoption?"
|
||
4. "Trenger dere audit trails for compliance? (Purview)"
|
||
5. "Trenger dere ALM pipelines? (Zone 2/3)"
|
||
|
||
**Når kunde sier "Vi er bekymret for oversharing", spør:**
|
||
1. "Har dere gjort SharePoint oversharing assessment? (SAM Data Access Governance reports)"
|
||
2. "Har dere sensitivity labels deployed? (Purview)"
|
||
3. "Trenger dere external sharing blocked for pilot? (DLP policies)"
|
||
4. "Skal vi følge Microsoft oversharing blueprint (Pilot → Deploy → Operate)?"
|
||
|
||
### Verification checklist før produksjonsdeploy
|
||
|
||
**Governance controls:**
|
||
- [ ] Zoned governance strategy definert (Zone 1/2/3 og tilhørende policies)
|
||
- [ ] DLP policies konfigurert på tenant-level og environment-level
|
||
- [ ] Environment routing konfigurert (makers routes til riktig environment)
|
||
- [ ] Security groups opprettet (Makers, Reviewers, Admins per zone)
|
||
- [ ] Dataverse security roles assigned (Copilot Author role til makers)
|
||
|
||
**Data protection:**
|
||
- [ ] Microsoft Purview sensitivity labels deployed og enforced
|
||
- [ ] SharePoint oversharing assessment fullført (SAM reports)
|
||
- [ ] Retention policies konfigurert (conversation transcripts)
|
||
- [ ] Audit logging aktivert (M365 Copilot og Copilot Studio activities)
|
||
|
||
**Lifecycle management:**
|
||
- [ ] ALM pipelines konfigurert for Zone 2/3 environments
|
||
- [ ] Approval workflows definert (IT coach review, IT admin approval)
|
||
- [ ] Agent inventory review prosess etablert (monthly cleanup)
|
||
- [ ] Orphaned agent detection og removal policy
|
||
|
||
**Compliance:**
|
||
- [ ] Data residency verifisert (Norway region for environments og Azure OpenAI)
|
||
- [ ] GDPR compliance validated (processing activities record i Purview)
|
||
- [ ] Customer-Managed Keys (CMK) konfigurert (hvis required for sensitive data)
|
||
- [ ] Network isolation konfigurert (VNET support, IP firewall hvis required)
|
||
|
||
**Monitoring:**
|
||
- [ ] Viva Insights Copilot Dashboard konfigurert (adoption metrics)
|
||
- [ ] Power Platform admin center capacity alerts konfigurert
|
||
- [ ] Microsoft Purview audit alerts konfigurert (abnormal activity detection)
|
||
- [ ] Cost monitoring dashboards etablert (storage, AI Builder credits)
|
||
|
||
**Communication:**
|
||
- [ ] Maker welcome message konfigurert (privacy og compliance requirements)
|
||
- [ ] Agent Store governance kommunisert til brukere (self-service policies)
|
||
- [ ] IT support runbook opprettet (agent issues, access requests)
|
||
- [ ] Pilot feedback loop etablert (iterative governance improvement)
|
||
|
||
### Integration med eksisterende enterprise governance
|
||
|
||
**Active Directory / Entra ID:**
|
||
- Security groups for Zone-based access control
|
||
- Conditional Access policies for Copilot apps (krever MFA, compliant device)
|
||
- Group-based licensing for M365 Copilot og Copilot Studio
|
||
|
||
**IT Service Management (ServiceNow, etc):**
|
||
- Agent deployment requests via ITSM ticket workflow
|
||
- Change management process for prod deployments (Zone 3)
|
||
- Incident management for agent issues
|
||
|
||
**Azure Policy:**
|
||
- Enforce Power Platform environment creation policies (allowed regions, naming conventions)
|
||
- Enforce Customer-Managed Keys (CMK) for sensitive environments
|
||
- Cost management policies (budget alerts for Dataverse storage)
|
||
|
||
**GitOps (Azure DevOps, GitHub):**
|
||
- ALM pipelines triggered via Git commits (agent solutions stored in source control)
|
||
- Code review gates før prod deployment (Zone 3)
|
||
- Infrastructure-as-Code (IaC) for environment provisioning (Terraform, Bicep)
|
||
|
||
---
|
||
|
||
## Kilder og verifisering
|
||
|
||
### Microsoft Learn dokumentasjon
|
||
|
||
**M365 Copilot governance:**
|
||
- [Agent installation in Microsoft 365 Copilot](https://learn.microsoft.com/en-us/copilot/microsoft-365/copilot-agent-install) — **Verified** (2026-02)
|
||
- [Manage agents for Microsoft 365 Copilot in the Microsoft 365 admin center](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-copilot-agents-integrated-apps) — **Verified** (2026-02)
|
||
- [Microsoft 365 Copilot reporting options for admins](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-reports-for-admins) — **Verified** (2026-02)
|
||
- [Set up Microsoft 365 Copilot and assign licenses](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-setup) — **Verified** (2026-02)
|
||
- [Address oversharing concerns in Microsoft 365 Copilot deployment blueprint](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-blueprint-oversharing) — **Verified** (2026-02)
|
||
|
||
**Copilot Studio governance:**
|
||
- [Implement a zoned governance strategy](https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/sec-gov-phase2) — **Verified** (2026-02)
|
||
- [Secure your Copilot Studio projects](https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/sec-gov-phase3) — **Verified** (2026-02)
|
||
- [Key concepts - Copilot Studio security and governance](https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-and-governance) — **Verified** (2026-02)
|
||
- [Security FAQs for Copilot Studio](https://learn.microsoft.com/en-us/microsoft-copilot-studio/security-faq) — **Verified** (2026-02)
|
||
- [Manage your Copilot Studio projects, an overview](https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/sec-gov-intro) — **Verified** (2026-02)
|
||
|
||
**Agent Builder vs Copilot Studio:**
|
||
- [Choose between Microsoft 365 Copilot and Copilot Studio to build your agent](https://learn.microsoft.com/en-us/microsoft-365-copilot/extensibility/copilot-studio-experience) — **Verified** (2026-02)
|
||
- [Copy an agent to Copilot Studio](https://learn.microsoft.com/en-us/microsoft-365-copilot/extensibility/copy-agent-to-copilot-studio) — **Verified** (2026-02)
|
||
|
||
**Microsoft Purview integration:**
|
||
- [Microsoft Purview data security and compliance protections for generative AI apps](https://learn.microsoft.com/en-us/purview/ai-microsoft-purview) — **Verified** (2026-02)
|
||
- [How data is protected and audited in Microsoft 365 and Microsoft 365 Copilot](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-architecture-data-protection-auditing) — **Verified** (2026-02)
|
||
|
||
**Admin controls:**
|
||
- [Manage Microsoft 365 Copilot scenarios in the Microsoft 365 admin center](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-page) — **Verified** (2026-02)
|
||
- [Admin policies for Copilot Pages and Copilot Notebooks](https://learn.microsoft.com/en-us/microsoft-365/loop/cpcn-admin-configuration) — **Verified** (2026-02)
|
||
|
||
### PowerShell code samples
|
||
|
||
**DLP policies:**
|
||
- [New-DLPCompliancePolicy](https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-dlpcompliancepolicy) — **Verified** (2026-02)
|
||
- [New-FeatureConfiguration](https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-featureconfiguration) — **Verified** (2026-02)
|
||
|
||
**Teams policies:**
|
||
- [Manage Microsoft 365 Copilot in Teams meetings and events](https://learn.microsoft.com/en-us/microsoftteams/copilot-teams-transcription) — **Verified** (2026-02)
|
||
- [Manage Microsoft 365 Copilot in Teams calls](https://learn.microsoft.com/en-us/microsoftteams/copilot-teams-calling-transcription) — **Verified** (2026-02)
|
||
|
||
**Conditional Access:**
|
||
- [Create service principals for Copilot apps in Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-copilot-ai-security) — **Verified** (2026-02)
|
||
|
||
### Baseline knowledge (modellkunnskap)
|
||
|
||
**Licensing og pricing:**
|
||
- **Baseline** — Microsoft publiserer ikke norske priser offentlig, estimater basert på US pricing og valutakurs (jan 2026)
|
||
- Verifiser med Microsoft partner eller Microsoft Volume Licensing for nøyaktige priser
|
||
|
||
**Offentlig sektor Norge:**
|
||
- **Baseline** — Schrems II compliance, GDPR Article 30, Arkivverkets retentionskrav (standard patterns i norsk offentlig sektor)
|
||
|
||
### Confidence markers
|
||
|
||
- **Verified** — Informasjon hentet direkte fra Microsoft Learn dokumentasjon via MCP microsoft-learn search/fetch (2026-04)
|
||
- **Baseline** — Informasjon basert på modellkunnskap (januar 2025), ikke verifisert via MCP
|
||
- **Estimat** — Kostnadsberegninger basert på US pricing og estimated valutakurs, krever verifikasjon
|
||
|
||
**MCP-statistikk:**
|
||
- 3 microsoft_docs_search calls
|
||
- 2 microsoft_docs_fetch calls
|
||
- 1 microsoft_code_sample_search call
|
||
- 25+ unike Microsoft Learn URLs referert
|
||
- 15+ PowerShell code samples inkludert
|