MC1476316: Microsoft 365 Copilot Adds Create, Update, and Delete Actions to Federated Connectors

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
60
0 25 50 75 100
HIGH IMPACT • REVIEW RECOMMENDED
Recommended Action:
Review the update and plan any required actions before rollout.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Microsoft 365 AdminsSecurity TeamsCompliance TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This update introduces write/delete actions through federated Copilot connectors, creating security, compliance, and governance considerations. Admins must review enabled connectors, assess risk, and potentially disable ones not meeting organisational requirements. Default user confirmation reduces immediate risk, but policy and configuration reviews are necessary. User impact is moderate since these actions occur within Copilot with explicit consent.
70
🛡️ Admin Impact
40
👥 User Impact
60
Urgency
55
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Copilot connectors will soon support create, update, and delete actions in third-party services. Worth checking connector settings and approval flows before rollout.
👥

END USERS

Users may see options to create, update, or delete data in linked third-party services during Copilot tasks.
🛡️

IT ADMINS

Review federated connectors and disable any that do not meet your security or compliance requirements.
📅

ROLLOUT TIMELINE

Upcoming:
October 2026

📢 Official Microsoft Message Center Announcement


Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions
Message ID: MC1476316

[What and why]

Federated Copilot connectors currently allow Microsoft 365 Copilot to retrieve data from third-party services in real time. With this update, supported connector tools that create, update, and delete content in those services will become available in Microsoft 365 Copilot experiences, helping users complete tasks without leaving Copilot. Actions are performed using the signed-in user’s account and permissions in the third-party service, and by default each create, update, or delete action requires the user’s explicit confirmation before it runs. Administrators can review each connector’s read and write/delete tools in the Microsoft 365 admin center and disable connectors that do not meet their organization’s requirements.

[Rollout schedule]

  • General Availability (Worldwide): Beginning in early October 2026 and expected to complete by late October 2026

[Impact on your organization]

Who is affected

  • Organizations that have federated Copilot connectors enabled
  • Users who connect federated Copilot connectors to supported third-party services
  • Administrators who manage federated Copilot connectors in the Microsoft 365 admin center

Platforms and services

  • Microsoft 365 Copilot Chat
  • Microsoft 365 admin center
  • Connected third-party services

What will happen

  • Supported connector tools that create, update, or delete content in third-party services will become available in supported Microsoft 365 Copilot experiences.
  • Available actions depend on the tools exposed by the connector publisher.
  • Federated Copilot connectors used in Researcher will remain read-only.
  • Users must authenticate to the third-party service before using authenticated connector capabilities.
  • User approval is required before create, update or delete actions
  • Before an action runs, Copilot displays the action and the parameters that will be sent to the third-party service.
  • Users can select Cancel, Allow once, or Always allow for a specific tool.
  • If a connector publisher adds or changes a tool that can create, update, or delete content, that tool returns to a state that requires approval.
  • Users can review or reset tool permissions in Copilot Settings > Sources.
  • If a user does not approve an action, the action is not performed.
  • Existing federated connector availability controls continue to apply.
  • A new MCP tools section will be available on each federated connector details page in the Microsoft 365 admin center.
  • Administrators can review the tools exposed by the connector, including tools that can modify or delete data.

Federated Copilot connectors continue to access external data in real time using the user’s identity and permissions. External data is not indexed into Microsoft 365.

[Action required and recommendations]

No action is required to receive this feature.

We recommend that administrators:

  • Review enabled federated Copilot connectors to determine which connectors may expose tools that create, update, or delete content.
  • Review connector capabilities against organizational security, compliance, and acceptable-use requirements.
  • Disable connectors that do not meet organizational requirements.
  • Review agreements with third-party providers, including applicable licensing, privacy, data residency, and acceptable-use requirements.
  • Update user and help-desk guidance so users understand that actions are performed using their permissions in the third-party service.
  • Review the updated Microsoft 365 Copilot connectors Terms of use.

Learn more

[Compliance considerations]

QuestionAnswer
Does the change alter how existing customer data is processed, stored, or accessed?Yes. Supported federated Copilot connector tools can create, update, and delete content in connected third-party services using the signed-in user’s permissions. External data continues to be accessed in real time and is not indexed into Microsoft 365.
Does the change introduce or significantly modify AI/ML or agent capabilities that interact with customer data?Yes. In addition to retrieving information, Microsoft 365 Copilot can invoke supported connector tools that create, update, or delete content in connected third-party services.
Does the change add any integration to third-party software products?Yes. Microsoft 365 Copilot can invoke supported tools exposed by federated Copilot connectors that create, update, or delete content in connected third-party services.
Does the change include an admin control?Yes. Existing connector availability controls continue to apply, and administrators can review connector tools and disable connectors that do not meet organizational requirements.
Does the change allow users to enable or disable the feature themselves?Yes. Users can manage approval preferences for connector tools and can review or reset tool permissions through Copilot Settings > Sources.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update