Microsoft's New Teams AI Agent Can Create Accounts and Reset Passwords. Should You Turn It On?

Microsoft's New Teams AI Agent Can Create Accounts and Reset Passwords. Should You Turn It On?

· by IDE Solutions

Say you need to add three new hires to Microsoft 365 this week, each with the right license, the right group, and a password that will not land in someone's inbox in plain text. If you could just type that sentence into a Teams chat window and have it done, correctly, in under a minute, would you let a piece of software do it? Microsoft is betting the answer for a lot of small businesses is yes. The Microsoft 365 Admin agent went generally available in 2026 for anyone holding a built-in administrator role, and it now sits inside Teams itself rather than buried in a separate admin portal only IT people ever open.

For a company with no dedicated IT department, that is a genuinely useful change. It is also a new kind of account to think about, because the agent that does the work is, technically, its own identity with its own access. Whether that trade is worth making depends on what you let it touch, which is exactly what this article walks through, alongside where our AI advisory work tends to focus when a business asks us to turn features like this on.

What the agent actually does

The Admin agent is built into Microsoft 365 Copilot Chat and the admin center, and it is pre-installed for anyone with a built-in administrator role: Global Administrator, User Administrator, Teams Administrator, and a handful of others. In practice that means a manager who was quietly promoted into "the person who deals with Microsoft 365" can type a plain request such as "add three new sales hires with Business Premium licenses and put them in the Sales team" and the agent drafts the change, shows what it is about to do, and waits for a confirmation click before it runs.

The task list is ordinary admin work: creating accounts, assigning and reclaiming licenses, resetting passwords, checking service health, and answering "why can't this person access the shared mailbox" style questions without a support ticket. None of it is new capability. What is new is that it no longer requires knowing where the setting lives, or which of the eleven different admin roles actually controls it. That is the part that matters for a ten-person company: the agent removes the specialist knowledge requirement, not the underlying complexity.

The same interface also handles the less glamorous half of admin work: reclaiming a license from someone who left three months ago and was quietly forgotten, checking whether a service outage is Microsoft's problem or a local one before opening a ticket, or pulling a quick answer on why a shared calendar stopped syncing. None of these are urgent enough to justify calling in outside help, but each one used to mean either digging through the admin center yourself or letting it sit unresolved for a week. Folding them into a chat window a manager already has open all day is arguably the more useful change than the account-creation example Microsoft leads with.

Why this is worth real money to a small business

Every small business we work with underestimates how much owner or office-manager time goes into routine Microsoft 365 administration, precisely because it happens in small, interrupting chunks rather than one visible block. Onboarding a new hire correctly, license, groups, mailbox permissions, forwarding rules, typically eats thirty to sixty minutes when someone unfamiliar with the admin center does it, longer if a setting is wrong and has to be found and undone. Multiply that by a hiring season, or by a client of ours who onboards four to six people a month, and it becomes a part-time job nobody budgeted for.

By our own rough math, a business paying a manager or office lead around 35 EUR an hour and onboarding five people a quarter is spending close to 700 EUR a year just on the mechanical part of account setup, before anything is done wrong and has to be fixed. That figure ignores the bigger cost, which is the manager's attention being somewhere other than the customer or the product for that half hour.

A chat-based agent that gets the routine eighty percent right on the first try does not replace that judgement, but it does compress the mechanical part of the task from minutes of clicking through menus to a sentence and a confirmation. For a business with no IT hire, that is time that goes back into running the business, not learning where Microsoft moved a setting this quarter.

What the agent will not do for you

The agent executes changes you approve. It does not decide what your Microsoft 365 tenant should look like. It will not tell you that the marketing intern has been a Global Administrator for the past two years and should not be, or that your conditional access policy still allows sign-in from any country because nobody ever narrowed it. Those are judgement calls that come from someone who has looked at your whole tenant, not just the single task in front of them.

That is roughly the line between what the agent covers and what managed Microsoft 365 support covers. The agent speeds up the individual task. A managed provider is accountable for whether the tenant as a whole still makes sense six months later, after a dozen small changes like this one have quietly accumulated.

The catch: the agent is a new identity, and identities need governing

Here is the part that gets skipped in most of the coverage. An AI agent that can create accounts and touch licenses does not run on magic, it runs on a real identity with real permissions, and Microsoft has built an entire separate product, Agent 365, just to keep track of agents like it across a tenant. That product exists because the pattern security teams keep finding is the same one that plagues human accounts: permissions granted for a project that ended months ago and never removed, an identity nobody remembers authorising, access nobody is reviewing.

A small business with one admin and no security function is exactly the environment where that kind of drift goes unnoticed the longest. The agent itself respects the admin role it is attached to and asks for confirmation before making a change, which is the right default. But "the agent behaves correctly" and "the human holding the admin role has more access than the business needs" are two separate problems, and only a proper Microsoft 365 security assessment answers the second one.

What to check before you turn it on

None of this means avoid the agent, it means turn it on deliberately rather than by default. Five things worth confirming first:

  • Who actually holds an admin role. Review the list before you hand any of them a tool that acts faster than a person would notice a mistake.
  • Whether confirmations are actually being read. A confirmation prompt only protects you if someone reads it instead of clicking through on habit.
  • What the audit log captures. Every action the agent takes should be traceable to the admin who approved it, not just to "the agent".
  • Whether license and group changes get a second look. Fast onboarding is only good if a mistake is caught the same day, not the same quarter.
  • Whether this is your only line of defence. An agent that speeds up admin work is not a substitute for conditional access, MFA, or a backup plan if an admin account itself is compromised.
  • Who is on the hook when something goes wrong. Decide in advance whether the person who clicked confirm, the vendor, or your IT provider owns the fix if a license or permission change breaks something downstream.

Quick answers

Does the Admin agent cost extra?

No. It is included for anyone already holding a built-in Microsoft Entra administrator role, at no additional license cost.

Can it make changes without approval?

It is designed to show the proposed change and wait for a confirmation before executing it, and it operates within the permissions of the admin role it is attached to.

Does a small business need Agent 365 too?

Not on day one. What matters first is knowing who holds admin access and reviewing it regularly. Agent-specific governance tooling becomes worth the setup once a business is running several AI agents, not just one.

Does the agent work outside Teams too?

Yes. It is also available directly in the Microsoft 365 admin center and in Copilot Chat outside Teams. Being reachable from Teams simply means you do not have to leave the app most people already have open all day.

We help you decide what to automate and what to lock down

Before you hand an AI agent the keys to your tenant, we check who currently holds admin access, whether that access still matches who needs it, and what a mistake, human or automated, would actually be able to reach.

Where the answer is "more than it should", we fix it: role cleanup, conditional access, and a short written policy for what gets automated and what still needs a person.

More Articles