Review the update and plan any required actions before rollout.
Primary Audience
Why this score?
AT A GLANCE
END USERS
IT ADMINS
ROLLOUT TIMELINE
October 2026
📢 Official Microsoft Message Center Announcement
Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions
Message ID: MC1476316
[What and why]
Federated Copilot connectors currently allow Microsoft 365 Copilot to retrieve data from third-party services in real time. With this update, supported connector tools that create, update, and delete content in those services will become available in Microsoft 365 Copilot experiences, helping users complete tasks without leaving Copilot. Actions are performed using the signed-in user’s account and permissions in the third-party service, and by default each create, update, or delete action requires the user’s explicit confirmation before it runs. Administrators can review each connector’s read and write/delete tools in the Microsoft 365 admin center and disable connectors that do not meet their organization’s requirements.
[Rollout schedule]
- General Availability (Worldwide): Beginning in early October 2026 and expected to complete by late October 2026
[Impact on your organization]
Who is affected
- Organizations that have federated Copilot connectors enabled
- Users who connect federated Copilot connectors to supported third-party services
- Administrators who manage federated Copilot connectors in the Microsoft 365 admin center
Platforms and services
- Microsoft 365 Copilot Chat
- Microsoft 365 admin center
- Connected third-party services
What will happen
- Supported connector tools that create, update, or delete content in third-party services will become available in supported Microsoft 365 Copilot experiences.
- Available actions depend on the tools exposed by the connector publisher.
- Federated Copilot connectors used in Researcher will remain read-only.
- Users must authenticate to the third-party service before using authenticated connector capabilities.
- User approval is required before create, update or delete actions
- Before an action runs, Copilot displays the action and the parameters that will be sent to the third-party service.
- Users can select Cancel, Allow once, or Always allow for a specific tool.
- If a connector publisher adds or changes a tool that can create, update, or delete content, that tool returns to a state that requires approval.
- Users can review or reset tool permissions in Copilot Settings > Sources.
- If a user does not approve an action, the action is not performed.
- Existing federated connector availability controls continue to apply.
- A new MCP tools section will be available on each federated connector details page in the Microsoft 365 admin center.
- Administrators can review the tools exposed by the connector, including tools that can modify or delete data.
Federated Copilot connectors continue to access external data in real time using the user’s identity and permissions. External data is not indexed into Microsoft 365.
[Action required and recommendations]
No action is required to receive this feature.
We recommend that administrators:
- Review enabled federated Copilot connectors to determine which connectors may expose tools that create, update, or delete content.
- Review connector capabilities against organizational security, compliance, and acceptable-use requirements.
- Disable connectors that do not meet organizational requirements.
- Review agreements with third-party providers, including applicable licensing, privacy, data residency, and acceptable-use requirements.
- Update user and help-desk guidance so users understand that actions are performed using their permissions in the third-party service.
- Review the updated Microsoft 365 Copilot connectors Terms of use.
Learn more
- Federated connectors overview – Microsoft 365 Copilot connectors | Microsoft Learn will be updated before release
[Compliance considerations]
| Question | Answer |
| Does the change alter how existing customer data is processed, stored, or accessed? | Yes. Supported federated Copilot connector tools can create, update, and delete content in connected third-party services using the signed-in user’s permissions. External data continues to be accessed in real time and is not indexed into Microsoft 365. |
| Does the change introduce or significantly modify AI/ML or agent capabilities that interact with customer data? | Yes. In addition to retrieving information, Microsoft 365 Copilot can invoke supported connector tools that create, update, or delete content in connected third-party services. |
| Does the change add any integration to third-party software products? | Yes. Microsoft 365 Copilot can invoke supported tools exposed by federated Copilot connectors that create, update, or delete content in connected third-party services. |
| Does the change include an admin control? | Yes. Existing connector availability controls continue to apply, and administrators can review connector tools and disable connectors that do not meet organizational requirements. |
| Does the change allow users to enable or disable the feature themselves? | Yes. Users can manage approval preferences for connector tools and can review or reset tool permissions through Copilot Settings > Sources. |
Source: Microsoft Message Center • Analysed by MWPro


