Agents & Automation

Microsoft Autopilot enters private preview as a persistent background agent inside M365

Microsoft's renamed Scout agent, now called Autopilot, gets its own identity, memory, and workspace inside M365: and keeps working when you log off.

agents automation category

Microsoft announced on 25 September 2026 that Scout, the always-on personal agent it introduced in June 2026, has been renamed Autopilot and is expanding to private preview and Frontier access. The name change reflects a meaningful increase in scope: Autopilot is no longer just an experimental desktop companion. It is a governed, persistent background agent that lives inside your organisation’s Microsoft 365 tenant, maintains its own identity and memory, and carries on working after you have closed your laptop.

What Autopilot actually does

The practical pitch is straightforward. You assign Autopilot a role, give it an objective, and it gets on with the work without needing a prompt each time. It monitors Teams channels, reads Outlook threads, pulls data from Dynamics 365, and surfaces what matters. If a project goes quiet for several days, Autopilot picks it back up. You can @mention it in a conversation the same way you would a colleague, and it will respond in context.

Microsoft demonstrated a version named “Dot” that monitored Black Friday preparations, pulling from email, Teams discussions, and Dynamics 365 inventory records simultaneously. That cross-service reach is handled through Work IQ, which queries across email, calendar, Teams, and documents using AI reasoning rather than requiring you to specify where to look.

The scheduling side is more granular than it might sound. Heartbeat mode runs a recurring prompt on a configurable schedule: every 15 minutes, 30 minutes, one hour, or two hours. You set the prompt, the interval, the working days, and the working hours. The agent runs on that cadence whether you are at your desk or not.

Its own identity, not a shared service account

The governance design is probably the most consequential technical detail here. Autopilot is issued a proper Entra identity, complete with a name, role, and defined purpose. That means every action it takes is attributable and auditable under your existing Microsoft Purview policies. Sensitivity labels and data loss prevention rules are enforced before anything is sent or written. Credentials are scoped to the task and redacted from logs.

Satya Nadella put it plainly in a presentation ahead of the announcement: “Every agent has to have an identity. Everything it does needs to be observed.”

That framing matters for IT and security teams. An agent that sends messages autonomously, monitors channels, and pulls from Dynamics 365 is a new kind of account on your network. Microsoft says the permissions, audit trail, and governance controls are all in place under the Agent 365 framework. What Microsoft has not yet published in detail is the approval workflow that governs outbound messages or exactly how Autopilot activity surfaces in audit logs. Those specifics will matter when admins are deciding how much latitude to give it.

What this means for you

If you are a knowledge worker, the most immediate change is that recurring, monitoring-heavy tasks become something you can delegate. Tracking a slow-moving procurement thread, chasing updates across three Teams channels, or keeping an eye on a project that has stalled, these are the kinds of jobs Autopilot is designed for. You set the goal and the constraints; it handles the watching.

If you are an IT administrator, Autopilot sits inside your tenant with real permissions, which means real governance obligations. Frontier enrolment is required, as is a Microsoft 365 Copilot licence, a GitHub Copilot Business or Enterprise licence, and an Intune-managed device. You will need to think about Autopilot instances the same way you think about service accounts: scoped permissions, monitored activity, and a clear owner.

If you manage budgets or oversee AI spend, the billing model is worth understanding before rollout. Everyday Copilot chat remains on per-user subscription licences. Autopilot, along with the new Cowork and Code features, runs on usage-based billing through Copilot Credits. Microsoft has not published detailed per-task pricing for Autopilot specifically, but has confirmed that charges reflect the model used, the context retrieved, the tools invoked, and execution time. New FinOps for AI tooling is being introduced alongside this to help track and manage that spend.

Managed hosting for what Autopilot builds

Alongside Autopilot, Microsoft announced Microsoft Copilot Managed Runtime, now in public preview. This is a hosting layer that allows code created inside Copilot to run securely within your organisation’s Microsoft 365 environment, under IT management. If Autopilot or the new Code feature generates an application or automation, Managed Runtime gives it a governed place to run rather than relying on external infrastructure or a developer setting up their own hosting.

Availability

Autopilot is entering private preview at the end of September 2026, with Frontier access also opening at that point. It requires a Microsoft 365 Copilot licence plus a GitHub Copilot Business or Enterprise licence, admin enrolment in Frontier, and an Intune-managed device. Broader availability has not been dated.

Microsoft Copilot Managed Runtime is in public preview from 25 September 2026.

The security and governance questions around an agent that acts autonomously and contacts colleagues on your behalf are real, and Microsoft has been transparent that some specifics are still to come. For organisations already running Frontier, the private preview is worth evaluating carefully, starting with a tightly scoped test case rather than a broad deployment.