An organization discovers dozens of unused Copilot agents with broad Graph permissions. What is the most appropriate lifecycle action?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — zombie agents with big permissions are free attack surface. Retire them and keep living agents owned and reviewed.
Full explanation below image
Full Explanation
Unused agents with broad permissions increase risk if credentials or consent are abused. Administrators should retire/disable unused agents, reduce scopes, and require owners to attest continued need. Expanding consent, pinning unused agents, or deleting the tenant are wrong. Pair lifecycle reviews with inventory dashboards and least-privilege consent policies.