Copilot Studio Friction

Get notified when this record changes

One email when the status or the fix changes — double opt-in, no tracking, unsubscribe in every email.

Other agents can use your agent's tools and knowledge — without a trace

Mitigatedsince 8 July 2026

Last verified

Details & related

Assessment

Confidence
CorroboratedMultiple independent sources describe the same behaviour.
Severity
Degrading
Typical time lost
Hours

Identification

Security defaultsGovernance & DLP

Verification & changes

  1. Verified

    Doc check by human: Zenity primary post plus security-press and forum corroboration reviewed via search on 2026-07-08; default-on and zero-Activity-tab behavior still reported. Direct fetch of the Zenity page was blocked; content confirmed through search. Test-tenant repro of the default is pending.

  2. Change

    Provisionally approved by the Product Owner; external LLM quality review pending.

  3. Change

    Initial record created from the seed dossier (migration wave 1).

Are you in the right place?

  • You build a new agent and keep the default settings.
  • The "Connected agents" option is on, and you did not enable it.
  • Other agents in the same environment can call your tools, knowledge sources, and topics.
  • The called agent's Activity tab shows nothing for those calls.
  • You cannot find a view of which agents connected to yours.

If instead your admin actions never reach the audit log → see Admin actions are missing from the audit log. If instead a public agent leaks data to strangers → see A publicly reachable agent leaks data.

What's happening

Connected agents let one agent call another agent's tools, knowledge, and topics. On new agents, this option is on by default, as security researchers documented. So any other agent in the same environment can reach the parts you shared. The called agent's Activity tab records none of these calls. The platform also shows no map of which agents connected to which. You cannot see who used your agent, or what they reached. Picture an office with a connecting door left unlocked by default. Colleagues can walk in, and the visitor log stays empty. Microsoft has not published a statement on this default, as of 2026-07-08.

For technicians

Zenity Labs documented the feature, introduced with the 2025 build, in December 2025. Their finding: a connected agent runs in the caller's session context. A malicious agent can read intermediate outputs and inject instructions into the reasoning chain. There is no native topology view, and no admin approval workflow for connections. The only current control is manual review and turning the feature off. Note the source's commercial interest here. Zenity sells the visibility tooling whose absence it documents. That interest does not disprove the finding, which security press corroborated in December 2025. Microsoft's statement on the default remains outstanding, as of 2026-07-08.

How to fix it

Solution 1

Community workaround

Turn off connected agents when you don't need them

  1. In Copilot Studio, open the agent you want to protect.
  2. Open "Settings".
  3. Open "Generative AI".
  4. Find the "Connected agents" option.
  5. Turn "Connected agents" off.

✅ You should now see: the "Connected agents" option showing as off for this agent.

  1. Repeat for every agent that does not need to be called by others.

Solution 2

Community workaround

Keep the shared surface minimal

Use this when you do need connected agents.

  1. List the tools, knowledge sources, and topics your agent exposes.
  2. Remove every item that other agents do not need.
  3. Treat each enabled agent as reachable by anyone.
  4. For visibility today, weigh third-party tooling against its cost and access.

✅ You should now see: a short, deliberate list of shared items, not the defaults.

Check that it worked

Open a second agent in the same environment. Ask it to use the first agent's tools or knowledge. Expected: with connected agents off, the second agent cannot reach them. If you kept the feature on, confirm only intended items respond.

If it didn't work

  • The change has not propagated yet. Publish and settings changes can take time to apply. Recheck after a short wait.
  • You changed the wrong agent or environment. Confirm you edited the agent that holds the shared items.
  • Someone re-enabled the option. Another maker with edit rights can turn it back on. Set a review rhythm.
  • You expected a record of past calls. The Activity tab does not show connected-agent calls, so history stays empty.

Prevent it next time

  • Make a connected-agents check a hard step in your security publish gate.
  • Turn the option off by default, and enable it only for a named need.
  • Re-check the setting after every platform update, because defaults can change.

Evidence

  • Security researchlabs.zenity.io

    Zenity Labs documents that Connected Agents is on by default on new agents, that invoking a connected agent leaves zero entries in the called agent's Activity tab, and that no topology view exists.

  • Security researchcybersecuritynews.com

    Independent security press corroborates the default-on Connected Agents feature and the missing activity trail for connected-agent calls.

  • Security researchwindowsforum.com

    A synthesis notes no native topology view and no admin approval workflow, leaving manual review and disabling as the only current controls.