Share via


Turn off or restrict access to Project Manager agent and Project Manager agent chat in Planner

Overview

The Project Manager agent automates plan creation and task execution for teams. The Project Manager agent chat (previously "Copilot in Planner") offers an in-app natural language chat experience, allowing your users to request updates to their plans and receive summaries and insights from the plan content.

As an admin, you can control access to these features for your organization or restrict them to specific security groups.

Security and Privacy

Project Manager agent and Project Manager agent chat are built on Microsoft’s comprehensive approach to security, compliance, and privacy.

Project Manager agent plans to provide the same auditing capabilities as premium plans (previously Project for the Web projects). To learn more about these auditing capabilities, see Planner Premium audit log activities.

For more information about security and privacy in Microsoft 365 Copilot, see Data, Privacy, and Security for Microsoft 365 Copilot.

Prerequisites and licensing

Users must have the following license to access Project Manager agent in Planner:

After acquiring the license, follow the steps in Prerequisites for making Planner changes in Windows PowerShell topic to make Planner changes in Windows PowerShell.

Manage access to Project Manager agent and Project Manager agent chat in Planner

Note

The policy changes may require up to an hour to become effective.

Open PowerShell and run the following commands to manage access to users in Planner:

  • To turn off Project Manager agent and Project Manager agent chat for all users:

    Set-PlannerConfiguration -AllowPlannerCopilot $false
    
  • To turn on Project Manager agent and Project Manager agent chat for all users:

    Set-PlannerConfiguration -AllowPlannerCopilot $true
    
  • To turn on Project Manager agent and Project Manager agent chat for a specific security group:

    
    Set-PlannerConfiguration -AllowPlannerCopilot $true -PlannerCopilotAllowedGroupId <security group id> 
    

    Note

    Users who are members of the specified security group, including those in nested groups, will have access. If the Security Group ID is invalid, no users will have access, even if AllowPlannerCopilot is set to $true.

  • To revert to all users from previously restricting to a specific security group:

    Set-PlannerConfiguration AllowPlannerCopilot $true -PlannerCopilotAllowedGroupId $null 
    
  • To verify your settings, run the following command:

    Get-PlannerConfiguration
    

The value for -AllowPlannerCopilot returned by the Get-PlannerConfiguration command shows whether these features are turned on for your organization, such as:

  • AllowPlannerCopilot: True or False

  • PlannerCopilotAllowedGroupId: Displays the Security Group ID when these features are turned on for your organization

Behavior matrix

AllowPlannerCopilot PlannerCopilotAllowedGroupId Result
$false Not applicable 'OFF' for all users
$true $null (00000000-0000-0000-0000-000000000000) 'ON' for all users
$true valid security group ID 'ON' for users in the security group only (or nested members)
$true invalid security group ID  'OFF' for all users

Note

  • Changes may take up to 1 hour to reflect across your organization.

  • Ensure the Security Group ID is valid and corresponds to an existing group in Microsoft Entra ID.