Automate·Advanced·45 min·Updated Sep 30, 2026

Build a machine configuration recommendation agent

Build a Copilot Studio agent that recommends device settings for performance, security, and regulatory compliance based on a device's role and current configuration.

Download PDF

Microsoft 365

Works With

Prerequisites

A documented baseline configuration standard per device role/type

Business Outcome

More consistent device configuration across the fleet, reducing security gaps that come from manual, inconsistent setup.

Workflow Overview

SharePoint
Copilot Studio

Step 1: Document the baseline standardsSharePoint

Load your organization's configuration baselines per device role (a finance laptop's security requirements differ from a shared kiosk device) into the agent's reference source — recommendations are only useful if measured against a real, specific standard.

Step 2: Build the recommendation agentCopilot Studio

Have the agent take a device's current configuration and role, compare it to the applicable baseline, and return the specific settings that are out of compliance along with the recommended value for each.

Prompt idea:

This laptop is configured as a Finance-role device. Compare its current security and update settings against our Finance baseline, and list every setting that doesn't match, with the current value and the recommended value.

Step 3: Route recommendations to IT for review before applyingSharePoint

Post each device's recommended changes to a SharePoint review list an IT admin works through manually — never wire this agent to push configuration changes directly to a device.

A misclassified device role feeding the wrong baseline is an easy mistake to make, and applied automatically it could lock out or break a device that was actually fine.

Step 4: Track compliance improvement over timeSharePoint

Keep a dated snapshot of the compliant/non-compliant count by device role each time you run this, so you can chart the trend rather than only ever seeing a single point-in-time number.

A device type that keeps reappearing in the non-compliant list after repeated fixes points to a provisioning process problem worth fixing upstream, not just another one-off correction.

Check the work

  • Confirm the device's assigned role is actually correct before trusting a baseline comparison built on it.
  • Spot-check a sample of "compliant" (no-flag) devices manually to make sure the comparison logic isn't missing a setting.
  • Have IT validate that a recommended change doesn't conflict with a legitimate, documented exception for that specific device.

Source: Microsoft Copilot Scenario Library — IT (2026)

Expected Outcome

A specific configuration recommendation per device, mapped to the applicable standard, with the gap between current and recommended state stated clearly.

!

Is AI actually needed here?

Comparing a device's settings against a documented baseline and listing what doesn't match is a structured diff, not a judgment call — the same thing device-management tooling already does.

Non-AI alternative: Microsoft Intune's built-in compliance policies already flag any setting that doesn't match an assigned baseline, with no AI step required.

Related Workflows

WORK WITH LIMINALS

Make AI useful for your team.

Get practical help with AI consulting or ask about training courses for your team.