Building and customizing solutions using Microsoft 365 Copilot APIs and tools
The behavior matches an access-control issue rather than a publishing issue.
Supported facts from the documented behavior:
- Visibility in the store and actual usage access are separate controls. An agent can appear in Built by your org / Built for your org after admin approval, but access and use are still governed by tenant admin controls and sharing settings.
- Tenant admins can restrict who can access agents.
In the Microsoft 365 admin center under Agents > Settings > User access, admins can allow:
- All users
- No users
- Specific users/groups
- Org-wide sharing can also be restricted by admin policy.
Admins can control who is allowed to share agents with the organization:
- All users
- Specific users or groups
- No users
- Direct assignment working as Viewer is consistent with the platform behavior. Sharing an agent directly with users or groups adds them to the people with access list, and those users can then view/test or use the agent depending on the sharing mode. That aligns with the symptom where explicitly adding a user immediately resolves the error.
- Licensing can also block use of an agent even when the agent is shared. Users must have the Microsoft 365 Copilot license required for the capabilities configured in that agent. If the license doesn’t match the agent capabilities, attempts to use the agent can result in an error.
Based on the scenario, the most likely checks are:
- In Microsoft 365 admin center → Agents → Settings → User access, confirm the tenant is set to All users or that the affected users/groups are included in Specific users/groups.
- Verify the affected users are in any required allowed group if Specific users/groups is configured.
- Confirm the agent’s capabilities match the users’ available Microsoft 365 Copilot licensing.
- If immediate access is required, continue assigning the affected users or groups directly to the agent as a workaround, since direct sharing is behaving as expected.
If the agent is visible in Built by your org, users can use other org agents, and only explicit Viewer assignment makes this specific agent usable, the strongest documented explanation is that effective access is being limited by agent access/sharing controls rather than by publication status.
References: