What it does
Covers how agents get from a maker to users: publishing to yourself, sharing with named people, submitting for org-wide availability, or listing in the Agent Store and Microsoft commercial marketplace.
Key facts
- Publish scopes: just me, specific users/groups, or whole organisation.
- Org-wide publishing routes through the Microsoft 365 admin centre for approval before it's available.
- Broad distribution can go via the Agent Store and Partner Center/commercial marketplace for ISV scenarios.
- Agents are packaged as M365 app packages; the same validation applies as for Teams apps.
- Admins can block, allow, or pre-approve agents through Integrated Apps controls.
When to use / skip
Self and named-user publishing is fine for pilots. Go org-wide only once you've settled ownership, support, and lifecycle — a widely published agent nobody maintains is a liability.
Configuration decisions
- Publish scope and target audience.
- Whether it needs to be a marketplace/ISV listing or stays internal.
- Who owns approval and ongoing maintenance.
Gotchas
- Org-wide approval can sit in the admin queue for days — don't promise a go-live date that assumes instant sign-off.
- Updates re-trigger review; version and communicate changes so approvers aren't surprised.
- Blocked or unapproved agents fail silently for end users, who then log support tickets.
Consultant notes
- Publishing friction is the most underestimated part of an agent project — build the approval path into the plan early.
- Governance is the real story here: agree who signs off, who owns lifecycle, and how you retire stale agents.
- For ISVs, marketplace listing is a separate validation track with its own lead time; scope it apart from tenant publishing.
Review if publish scopes or admin approval flow change.