SharePoint Lists Become a Native Knowledge Source for Copilot Studio Agents
The most strategically important item this week is a roadmap change rather than a shipped feature: SharePoint lists are becoming a native knowledge source for Microsoft Copilot Studio agents, with a September 2026 target. Today, grounding an agent in list data means exporting it, standing up a connector, or writing custom plumbing to keep a copy in sync. The new capability lets a maker point a Copilot Studio agent directly at a list and have it reason over that data — tasks, inventory, customers, operational records — with no data movement and no integration code.
This matters because SharePoint lists are where a huge amount of an organization's structured, business-critical, constantly-changing data actually lives. A helpdesk agent that answers from a live ticket list, an inventory bot that reads current stock, or an onboarding assistant grounded in a checklist list all become buildable by a citizen developer rather than a project team. The data stays authoritative in the list, and the agent stays current because it reads the source rather than a stale export.
For an organization thinking deliberately about how to shape AI, this is a governance moment as much as a capability one. The lists that become knowledge sources are only as trustworthy as their data quality, column hygiene, and permissions. An agent that grounds on a messy list will confidently answer from messy data, and one pointed at an over-shared list can surface information the asker should never have seen.
What to do: Inventory the SharePoint lists most likely to become agent knowledge sources — the operational lists people already treat as sources of truth — and clean up their columns, validation, and permissions now, before September makes them one prompt away from an AI answer.
The Surveys Agent Retires August 31 as Survey Creation Moves Into Forms
A concrete, near-term deadline landed this week: the standalone Surveys agent in SharePoint and Microsoft 365 is being retired on August 31, 2026, with Copilot-powered survey creation folding into Microsoft Forms. Rather than maintaining a separate agent surface for building and distributing surveys, Microsoft is consolidating the experience where forms already live, and letting Copilot generate the survey from a natural-language description inside Forms.
For most organizations the practical impact is small but real. Any documentation, training material, or internal "how we collect feedback" runbook that references the Surveys agent by name will be pointing users at a dead end after month's end. Teams that had built a habit around the agent need to know the capability is not disappearing — it is moving — so the transition reads as a relocation rather than a loss.
The broader pattern is worth noting: Microsoft continues to prune single-purpose agents and reabsorb their functions into the primary apps, using Copilot as the connective tissue. Expect more of this consolidation, which generally reduces surface area and confusion but does churn the specific entry points users have memorized.
What to do: Update any internal guidance or training that references the Surveys agent, and point users to Copilot-assisted survey creation in Microsoft Forms before the August 31 retirement so no one hits a broken workflow.
The New SharePoint Experience and Its Permissions Report Change How Admins See Access
The new SharePoint experience, which became available for all customers to preview earlier this year from the SharePoint admin center under Settings, continues its rollout and is worth revisiting this week alongside a related admin capability that changes how permissions are audited. Paired with the modernized experience is a Permissions Report in the admin center under Data Access Governance that shows, for a given user, exactly which sites they can access — including both direct grants and access inherited through group membership.
That group-inheritance visibility is the meaningful part. Most access-related surprises in SharePoint come not from someone being granted a site directly but from a nested group, a hub association, or a broad "everyone" grant quietly extending reach. A report that resolves effective access down to the individual user turns a formerly manual, error-prone investigation into something an admin can answer in one place — a question that becomes far more pressing the moment lists and sites start feeding AI agents.
The through-line connecting this week's stories is that access governance is moving from a background hygiene task to a prerequisite for safe AI. As Copilot and Copilot Studio agents ground on more SharePoint content, "who can see this site" becomes "what will an agent reveal to this person," and tools that make effective permissions legible move from nice-to-have to essential.
What to do: Use the Data Access Governance permissions report to spot-check access for a few sensitive sites and any account tied to an AI agent, and treat over-broad group-based grants as issues to remediate before they become AI oversharing incidents.
SPFx Copilot Apps Advance Toward General Availability
For developers, the SharePoint Framework (SPFx) story continues to orient around AI extensibility rather than classic web parts. The SharePoint Copilot Apps capability that entered public preview earlier this summer is progressing toward general availability later in 2026, and the recent 1.23.2 release was a deliberately focused quality build meant to stabilize the platform and lay groundwork for the next wave of extensibility — including list and library panel customization and the edit-panel override capability.
The significance is directional. With SharePoint Add-Ins and Azure ACS retired and Content Security Policy enforcement now applied to custom SPFx solutions, SPFx is unambiguously the sanctioned path for extending SharePoint, and Microsoft is steering that path toward building Copilot-integrated apps rather than standalone components. Teams that maintain custom solutions should read the roadmap as a signal about where to invest new development effort.
Practically, the near-term work remains hygiene: staying current on the monthly security cadence, keeping npm audit clean, and confirming that any custom scripts load from CSP-approved sources so they are not silently blocked. The exciting capabilities are arriving, but they sit on top of a toolchain that has to be kept healthy first.
What to do: If you build custom SPFx solutions, track the 1.23.x releases for the panel-customization and Copilot Apps groundwork, and audit your solutions now to confirm every script source is CSP-approved so nothing breaks under enforcement.
Retirement Watch: Alerts Off, Designer 2013 Ending, OTP Countdown Continues
Several retirements are live or approaching and deserve a standing place on the admin calendar. SharePoint Alerts have now been turned off, with Microsoft directing customers to rebuild those notifications using Power Automate flows or SharePoint Rules; any lingering dependency on the old alerts is now a broken workflow rather than a future risk. Separately, SharePoint Designer 2013 has reached end of support and is being retired in a staggered fashion across Microsoft 365 environments, closing out one of the last remnants of the legacy customization era.
The largest clock still ticking is the retirement of the SharePoint One-Time Passcode (SPO OTP) and the transition to Microsoft Entra B2B (MC1243549). Phase 2 begins October 1 and completes by October 31. New external sharing has already routed through Entra B2B since the spring, but once OTP is gone, external recipients of older "specific people" links who lack a B2B guest account can be denied access until an internal user re-shares or a guest account is created.
Because the OTP remediation is inventory-driven, it takes real calendar time to work through, and the weeks before October are the runway. Auditing external shares now — rather than in late September — is the difference between a planned cleanup and a scramble when links start failing.
What to do: Confirm any business-critical notifications have been migrated off SharePoint Alerts to Power Automate or Rules, retire lingering SharePoint Designer 2013 usage, and start inventorying external "specific people" shares that lack Entra B2B guest accounts ahead of the October OTP deadline.
Sources
- SharePoint lists as a knowledge source for Copilot Studio agents — Microsoft 365 Roadmap (SharePoint)
- What's New in Copilot in SharePoint: August 2026 — Microsoft Community Hub
- Frequently asked questions about Copilot in SharePoint — Microsoft Support
- What's new for SharePoint – July 2026 — HANDS ON SharePoint
- Microsoft Introduces New SharePoint Experience — AdminDroid
- SharePoint 2026 Updates: AI Features, UX & Key Retirements — Peafowl IT
- SharePoint Framework (SPFx) roadmap update – July 2026 — Microsoft 365 Developer Blog
- SharePoint Framework v1.23.2 release notes — Microsoft Learn
- SharePoint Alerts retirement — Microsoft Community Hub
- Microsoft 365: Upcoming Changes and End-of-Support Milestones — AdminDroid
- MC1243549 - Retirement of SharePoint One-Time Passcode (SPO OTP) and transition to Microsoft Entra B2B — Microsoft 365 Message Center Archive