Copilot connectors are about to do more than just find information

Until now, the big promise of federated Copilot connectors has been fairly simple: let Microsoft 365 Copilot reach into another system and bring back current information without first copying or indexing that data in Microsoft 365.

That is useful, but it is still mostly a read-only experience. You ask a question, Copilot finds the information, and you take it from there.

Microsoft’s next update changes that. Where a connector provides the right tools, Copilot will be able to create, update and delete data in the connected system on a user’s behalf. Microsoft says support for these actions will begin rolling out in early October 2026.

In other words, Copilot is moving from “tell me what’s happening” towards “help me get this done”.

What is a federated Copilot connector?

A federated connector lets Copilot access information held in an external service in real time. It uses Model Context Protocol (MCP), and the information stays in its original system rather than being indexed into Microsoft 365.

Access also uses the signed-in person’s identity and permissions. So, in principle, Copilot should only be able to work with information and actions that person is already allowed to use. Admins can manage connector availability and governance through Microsoft 365.

Not every connector will suddenly support every action. The connector must expose the relevant tools, and the source system’s permissions still matter.

A few practical use cases

This update becomes much easier to understand when you picture an ordinary working day.

Updating a customer record

Imagine you have just finished a Teams meeting with a customer. Copilot could summarise the key points, find the customer in a connected CRM, update the opportunity stage and add a follow-up note. That removes a small piece of admin without asking someone to copy information between systems.

Creating and maintaining project tasks

A project manager could ask Copilot to find agreed actions from a meeting, create tasks in a connected project system, assign owners and update due dates when plans change. Instead of simply producing a list for someone else to enter, Copilot could complete the update.

Working with service requests

A support team might use Copilot to review a customer’s open requests, add a progress note or update the status of a ticket. With the right connector and permissions, a user could move the work along without leaving Microsoft 365 Copilot.

Cleaning up duplicate or outdated records

Delete actions could help remove a duplicate task, obsolete record or cancelled booking. This is also the example that should make organisations pause for a moment: deleting data is useful, but it deserves more care than simply reading it.

A user reviews and approves a Copilot action before an external system is updated

Microsoft 365 Copilot connected to external business systems

The important bit: governance before convenience

The potential time savings are obvious. The risks are fairly obvious too.

Before enabling action-capable connectors widely, organisations should understand exactly which systems are connected, which actions each connector makes available, and what different groups of users are permitted to change. It is also worth deciding where a human confirmation step is needed, especially for deletion, financial records, customer information or other sensitive data.

A sensible starting checklist would be:

  • Review permissions: make sure access in the source system is accurate and follows least-privilege principles.
  • Test with low-risk actions: begin with a small group and actions that are easy to reverse.
  • Set clear boundaries: decide which updates Copilot may carry out and which should remain manual.
  • Prepare users: teach people to review the target record, proposed change and context before confirming an action.
  • Monitor the rollout: check Microsoft’s documentation and your available connectors as support expands.

Why this matters

This may look like a technical connector update, but it signals a bigger shift in how people will use Copilot. Finding and summarising information saves time. Taking an action in the system where the work actually lives can remove an entire step from the process.

That does not mean handing everything over to AI. The best use cases will combine clear permissions, reliable source data, sensible review and people who understand what Copilot is doing.

For many teams, the first job is not to switch on every available action. It is to identify a few repetitive, low-risk updates where Copilot could genuinely make the day easier, then test them carefully.

If your team is exploring Microsoft 365 Copilot, 3grow’s practical Microsoft Copilot training can help users build useful habits and understand where human judgement still matters.

 

Sources

Discover more from Microsoft 365 Training by 3grow

Subscribe now to keep reading and get access to the full archive.

Continue reading