Exercise - Review, approve, and block a tool

Completed

Relecloud's Agent Tools registry has a pending tool request awaiting review, and a separate, already-available tool that a governance review flags as too risky to leave unrestricted.

Important

Prerequisites for this exercise:

  • A Microsoft 365 tenant with AI Administrator (or Global Administrator) access to the Agent Tools Registry and Requests tabs.
  • A pending tool request pre-seeded for the lab—seed one yourself if your lab doesn't provide it.

Task 1: Review and approve a pending tool request

  1. Sign in to the Microsoft 365 admin center at admin.microsoft.com with your AI Administrator account.
  2. Go to Copilot > Agent tools (or the equivalent Agent Registry Tools surface in your tenant), then select the Requests tab.
  3. Open the pending tool request and review its declared purpose, the data or systems it connects to, and the permissions it asks for.
  4. Select Approve, and grant the tenant-wide consent the tool requires.
  5. Confirm the tool now shows as Available on the main Tools tab—it's usable by agents across the tenant from this point forward.

Task 2: Block an unreviewed, risky tool

  1. Still on the Tools tab, locate the separate tool your governance review flagged as too risky to leave unrestricted.
  2. Select the tool, then select Block.
  3. Confirm the tool's status changes to Blocked and that agents tenant-wide can no longer invoke it.
  4. Reflect: Approving and blocking are the same governance action applied in opposite directions—both require a deliberate, reviewed decision rather than letting a tool sit in an ambiguous default state.

You've now approved one tool request with the tenant-wide consent it needed, and blocked a separate risky tool from tenant-wide use—the two sides of the same review discipline every tool in Relecloud's registry needs.