Copilot Studio Friction
Other agents can use your agent's tools and knowledge — without a trace
Last verified
Details & related
Assessment
- Confidence
- CorroboratedMultiple independent sources describe the same behaviour.
- Severity
- Degrading
- Typical time lost
- Hours
Identification
Verification & changes
Verified
Doc check by human: Zenity primary post plus security-press and forum corroboration reviewed via search on 2026-07-08; default-on and zero-Activity-tab behavior still reported. Direct fetch of the Zenity page was blocked; content confirmed through search. Test-tenant repro of the default is pending.
Change
Provisionally approved by the Product Owner; external LLM quality review pending.
Change
Initial record created from the seed dossier (migration wave 1).
Are you in the right place?
- You build a new agent and keep the default settings.
- The "Connected agents" option is on, and you did not enable it.
- Other agents in the same environment can call your tools, knowledge sources, and topics.
- The called agent's Activity tab shows nothing for those calls.
- You cannot find a view of which agents connected to yours.
If instead your admin actions never reach the audit log → see Admin actions are missing from the audit log. If instead a public agent leaks data to strangers → see A publicly reachable agent leaks data.
What's happening
Connected agents let one agent call another agent's tools, knowledge, and topics. On new agents, this option is on by default, as security researchers documented. So any other agent in the same environment can reach the parts you shared. The called agent's Activity tab records none of these calls. The platform also shows no map of which agents connected to which. You cannot see who used your agent, or what they reached. Picture an office with a connecting door left unlocked by default. Colleagues can walk in, and the visitor log stays empty. Microsoft has not published a statement on this default, as of 2026-07-08.
For technicians
Zenity Labs documented the feature, introduced with the 2025 build, in December 2025. Their finding: a connected agent runs in the caller's session context. A malicious agent can read intermediate outputs and inject instructions into the reasoning chain. There is no native topology view, and no admin approval workflow for connections. The only current control is manual review and turning the feature off. Note the source's commercial interest here. Zenity sells the visibility tooling whose absence it documents. That interest does not disprove the finding, which security press corroborated in December 2025. Microsoft's statement on the default remains outstanding, as of 2026-07-08.
How to fix it
Solution 1
Community workaroundTurn off connected agents when you don't need them
- In Copilot Studio, open the agent you want to protect.
- Open "Settings".
- Open "Generative AI".
- Find the "Connected agents" option.
- Turn "Connected agents" off.
✅ You should now see: the "Connected agents" option showing as off for this agent.
- Repeat for every agent that does not need to be called by others.
Solution 2
Community workaroundKeep the shared surface minimal
Use this when you do need connected agents.
- List the tools, knowledge sources, and topics your agent exposes.
- Remove every item that other agents do not need.
- Treat each enabled agent as reachable by anyone.
- For visibility today, weigh third-party tooling against its cost and access.
✅ You should now see: a short, deliberate list of shared items, not the defaults.
Check that it worked
Open a second agent in the same environment. Ask it to use the first agent's tools or knowledge. Expected: with connected agents off, the second agent cannot reach them. If you kept the feature on, confirm only intended items respond.
If it didn't work
- The change has not propagated yet. Publish and settings changes can take time to apply. Recheck after a short wait.
- You changed the wrong agent or environment. Confirm you edited the agent that holds the shared items.
- Someone re-enabled the option. Another maker with edit rights can turn it back on. Set a review rhythm.
- You expected a record of past calls. The Activity tab does not show connected-agent calls, so history stays empty.
Prevent it next time
- Make a connected-agents check a hard step in your security publish gate.
- Turn the option off by default, and enable it only for a named need.
- Re-check the setting after every platform update, because defaults can change.
Evidence
Security researchlabs.zenity.io
Zenity Labs documents that Connected Agents is on by default on new agents, that invoking a connected agent leaves zero entries in the called agent's Activity tab, and that no topology view exists.
Security researchcybersecuritynews.com
Independent security press corroborates the default-on Connected Agents feature and the missing activity trail for connected-agent calls.
Security researchwindowsforum.com
A synthesis notes no native topology view and no admin approval workflow, leaving manual review and disabling as the only current controls.