Skip to the content.

Personal blog. This site reflects my own testing and my own opinions. It is not an official Microsoft statement and it is not official Microsoft documentation in any way. For authoritative guidance always refer to Microsoft Learn.

TL;DR — Writing a business app is no longer the hard part. Any capable AI will produce one in minutes. The hard part in a large organisation is the boring question that follows: where does it run, whose identity does it use, what data can it touch, and who can see that it exists?

Copilot Managed Runtime (public preview) is Microsoft’s answer: a Microsoft-hosted runtime inside the Microsoft 365 tenant boundary where every app — whether a business user built it in the Microsoft 365 Copilot app (Code or Cowork), a maker in Copilot Studio, or a developer with any coding agent — gets Entra sign-in, governed data access, one inventory and one set of admin controls.

It is largely off by default: an admin sets up app governance and opens the creation paths in the Microsoft 365 admin center, and apps run on Power Apps Premium or Copilot Credits.

I built apps on it both ways: in Copilot Cowork, the natural route for business users, and with Claude Code — not a Microsoft AI — for the bigger ones. That says something about how open it is.

What this article is. An introduction and an opinion, grounded in a few days of hands-on use in a lab tenant. It is not a step-by-step guide and not an official Microsoft statement. The product is in preview and changes weekly; observations were last checked on 6 October 2026.

The problem nobody asked for, and everybody now has

A year ago, “can we build an app for that?” meant a backlog, a budget and a quarter. Today it means a prompt. Copilot, Claude, Codex, Lovable, Bolt, v0 — pick one, describe a deal tracker or a fee calculator, and you get a working web app before your coffee is cold.

That is wonderful, and in a large organisation it is also a problem:

Blocking AI app builders doesn’t work for long — people find a way, and the useful ideas go underground. The interesting question is not whether people will build apps with AI, but whether there is a safe, boring, enterprise-grade place for those apps to land.

What Copilot Managed Runtime is

In one sentence: a Microsoft-operated runtime in your Microsoft 365 tenant where internal web apps run with your identity, your data policies and your oversight, regardless of what built them.

 Microsoft 365 Copilot app ─┐
   Code · Cowork            │
 Copilot Studio            ─┤                      ┌─► Dataverse, SharePoint, Outlook, Teams,
 ms CLI + SDK with         ─┼─►  Managed Runtime  ─┼─► Work IQ (Microsoft 365 Copilot),
   GitHub Copilot,          │    Entra sign-in     └─► Copilot Studio agents, 1,500+ connectors
   Claude Code, Codex       │    governed data           — always as the signed-in user
 Lovable                   ─┘    one inventory

A few things make it feel different from “yet another hosting option”:

If you know Power Platform, this will feel familiar underneath: environments, connectors and data policies are the same machinery that governs Power Apps today. What is new is the code-first, AI-first front end, the Git-based build pipeline, the admin-center inventory and consumption billing.

It is (largely) off by default — and that is the right call

The runtime itself is present in every eligible tenant, but the doors into it are mostly closed until an administrator opens them. The developer command-line path is switched off by default; app building in Copilot Code and Cowork arrives through Microsoft’s early-access Frontier programme; and governance has to be set up. (Measured: in the lab tenant, nothing could be built from the command line until an administrator had done this. Per the documentation, app creation in Copilot Studio is the exception — on by default during the preview, and controlled from the same place.) In the Microsoft 365 admin center, Apps → Overview walks an admin through setting up app governance: it creates a governance group with Microsoft-managed default rules (who gets a personal development environment, which connectors and MCP servers apps may use, how widely apps may be shared, which content sources the browser may load) and lets the admin choose which creation paths are on — Cowork, Copilot Studio, the command line.

Microsoft 365 admin center, Apps overview: app governance group created, six managed apps, one environment group, two creation paths turned on

Apps overview in a lab tenant after setup: the governance group exists, six apps are in the inventory, two creation paths are on.

The defaults are conservative in a way security teams will appreciate. Out of the box, apps may use a curated list of Microsoft first-party connectors, and individual risky actions inside them — “send an arbitrary HTTP request”, “run a script” — are blocked. Opening up more is a deliberate admin decision.

One practical note for Power Platform administrators: the runtime places makers into personal development environments through environment routing, and once governance is initialised the catch-all routing rule becomes permanent. Design routing first.

Who pays, and how

To run an app, a user needs either a Power Apps Premium licence or access to Copilot Credits. Credits are metered per app launch and per data call — a tenth of a credit per call at the time of writing — and are granted through the same spending policies that already cover Copilot Cowork and Work IQ.

Copilot cost management: a spending policy that includes Copilot Managed Runtime among the services that consume Copilot Credits

Copilot → Cost management: “Copilot Managed Runtime” is one of the services a spending policy can cover.

The interesting consequence is economic. An app that thirty people open a few times a month costs a few euros on credits, where licensing every user would cost hundreds. Heavy, all-day apps flip the other way. (Reasoning, not measurement: the break-even I calculated from the published rates is roughly twenty thousand data calls per user per month. The runtime is a paid preview; check current pricing before you plan around it.)

What I built, and with what

To see whether the developer route holds up beyond a hello-world, I built four apps with Claude Code for an investment-management storyline, all with fictional data:

Portfolio Desk: a monitoring sweep turns Microsoft 365 content into risk signals per portfolio company

The AI part is where the “app versus chat” question gets an answer. A monitoring sweep asks Work IQ — Microsoft 365 Copilot’s work-data layer — to read the user’s mail, chats, meetings and files about every portfolio company and return structured signals: red, amber or green, with dated evidence and a suggested action. The app turns them into badges on the pipeline and, with one click, into a tracked request in the committee’s SharePoint list. A second button sends the deal to a Copilot Studio agent that drafts an investment-committee memo against the firm’s policy.

Chat would have answered the question once. The app makes the answer structured, repeatable, shared and actionable — and the data never leaves Microsoft 365, because every call runs as the signed-in user.

Two ways to build: Cowork for business users, Claude Code and its counterparts for technical ones

For business users the natural route is Copilot Cowork (and Code) in the Microsoft 365 Copilot app: describe the app in a chat, refine it in a live preview, publish and share. No tooling, no repository to think about — and the result lands in the same governed runtime as everything else. I used it for the simpler apps, and it is the part that gets a room full of non-developers leaning forward.

For more technical users there is a second route that doesn’t involve a Microsoft AI at all. The bigger apps here were written by Claude Code, driving Microsoft’s ms command line on a Linux server. That is not a workaround: Microsoft publishes the command line and SDK on npm, and a plugin for coding agents in its own GitHub repository that works with GitHub Copilot and Claude Code. Its skills turned out to be the best practical documentation available — how to wire Work IQ, how to bind Dataverse tables, which rules the sandbox enforces.

What it took in practice, at the level of “what kind of work” rather than a recipe:

I tested with Claude Code. Other AI coding tools — Codex, GitHub Copilot, Gemini-based agents, IDE assistants — will very likely work in a similar way: the path is a command line, an SDK and a React app, nothing specific to one model. Lovable already publishes into the runtime directly.

That openness is, to me, the most important design decision in the product. It says: build with whatever your people like; run it where you can govern it.

What to be honest about

It is a public preview, and it behaves like one:

None of that changes the shape of the idea. Team and departmental apps are a good place to start today; for business-critical processes, review the preview terms and the current state of the documentation first.

Takeaways

Written from hands-on use in a lab tenant, October 2026. Not official Microsoft guidance. The product is in preview — verify before relying on any of it. Corrections welcome — open an issue on the repository.


Written by Ondrej Stefka · LinkedIn

About this blog →