IT Help Desk Agent in Copilot Studio for Microsoft Teams
IT Partner builds a Tier-0/Tier-1 IT help desk agent in Microsoft Copilot Studio — starting from Microsoft's IT Helpdesk agent template, not a blank canvas — and publishes it to Microsoft Teams and Microsoft 365 Copilot in your own tenant. The agent answers from up to three of your IT knowledge sources with each user's SharePoint permissions respected, walks people through up to five guided request paths (password and MFA resets through your approved route, software and access requests, VPN, Wi-Fi and printer how-tos), collects the diagnostics a technician needs (device name, OS, error text, screenshot), and hands anything it cannot resolve to your ticketing system — ServiceNow, Jira Service Management, Freshservice, Zendesk or Halo — or to IT Partner's own help desk, with ticket status lookup where the connector supports it. Three weeks to go-live, then a 30-day tuning pass and a maker handover so your team can extend it. $6,950 fixed per project, quoted in writing before work begins; you pay after you approve delivery. Copilot Credits for users without a Microsoft 365 Copilot seat, and your ITSM licensing, are the vendors' charges and are not part of this fee.
What this engagement is
Every IT help desk carries the same top ten: "my password expired", "I got a new phone and MFA stopped working", "VPN won't connect from home", "how do I add the printer", "I need access to the finance site", "can you install Visio". The answers already exist — in a SharePoint IT site nobody reads, a how-to library, a policy PDF, a ServiceNow knowledge base — and a technician still retypes them ticket after ticket. Microsoft's IT Helpdesk agent template in Copilot Studio gives that problem a working starting shape: an agent that answers from your organization's knowledge, creates a ticket when the answer is not there, and lets the user check the ticket's status later. This service takes the template and makes it yours: grounded in the knowledge you actually have, wired to the request paths your ticket data says matter, connected to the ticketing system you already run, and published where your people already are — Microsoft Teams. Here is what a user sees. They open the agent in Teams (pinned to the app bar through an app setup policy if you want it there) or ask it inside Microsoft 365 Copilot, and type "VPN won't connect from home". The agent answers from your how-to article, with a link to it, and asks the questions a technician would ask: which device, which operating system, what the error says, and a screenshot where the channel allows attachments. If the article fixes it, the session ends there and the analytics record a resolution. If it does not, the agent files a complete ticket — description, category, the collected diagnostics — in ServiceNow, Jira Service Management, Freshservice, Zendesk or Halo, under the user's own identity where the connector supports user sign-in, and reads the ticket number back. A week later, "what's happening with my ticket?" returns the status from the same connection. The five request paths are authored topics — deterministic, testable, and the cheapest kind of interaction in Copilot Credits — while everything outside them uses generative answers over your three knowledge sources, with the agent saying plainly when it is escalating rather than guessing. Knowledge read from SharePoint respects each user's own permissions, so a restricted runbook does not leak through a chat window. The agent lives in a Power Platform environment in your tenant and belongs to you; nothing routes through IT Partner. Users who hold a Microsoft 365 Copilot license are not metered for agents inside Teams and Microsoft 365 Copilot — Microsoft's licensing guide includes Copilot Studio agents for Teams, SharePoint and Microsoft 365 Copilot with the seat. Users without a seat consume Copilot Credits, Microsoft's metered charge, either pay-as-you-go or from a capacity pack; we size that from your ticket volumes at kickoff and, for organizations that buy their Microsoft licensing through IT Partner, switch pay-as-you-go on at no charge under our Microsoft 365 Copilot Pay-as-You-Go Credits Setup. We do not promise a deflection rate: the agent's analytics show what it resolved, what it escalated and what it could not answer, and the 30-day tuning pass works from those numbers rather than from a slide. If you would rather not staff the human tier, our Remote Support Help Desk Service becomes the escalation target; after the tuning pass, Managed AI Agent Operations keeps the agent current month to month; and anything that outgrows the template shape is Custom Agent Development with Microsoft Copilot Studio.
Success criteria
What you receive
How the work unfolds
We read your 90-day ticket export with your help desk lead and rank the request categories by volume and repeatability, inventory the IT knowledge you have (SharePoint sites, how-to libraries, policies, ITSM knowledge base), and confirm the licensing position: who holds Microsoft 365 Copilot seats, whether a Copilot Studio capacity pack or pay-as-you-go billing plan is in place for everyone else, and which ITSM we are connecting to and with what identity.
You sign off the design record: the three knowledge sources, the five request paths, escalation rules, the test set and the pilot group. We create or select the Power Platform environment, confirm data-loss-prevention policies allow the connectors we need, register the ITSM connection (OAuth app registry in ServiceNow, API key in Freshservice, API token in Zendesk, Cloud site in Jira, API application in Halo), and stand up the agent from the template.
Knowledge sources connected and their permission behaviour checked; the five request paths authored as topics with diagnostic collection; the template's ServiceNow actions kept or replaced with your ITSM's connector or API; ticket creation and status lookup wired; Microsoft Entra authentication, generative-answer settings and content moderation configured; instructions and welcome experience tuned. We run the scripted test set daily and fix what fails.
The agent is published to the pilot group in Teams. Pilot users bring real problems for three to five working days while we watch transcripts, unanswered questions and escalations, and your help desk checks that the tickets arriving from the agent are complete enough to work without a call-back.
Pilot findings fixed and re-tested; the app approved in the Teams admin center and published to the agreed audience, pinned where you asked; the analytics baseline captured; the two-hour maker handover delivered with the runbook; an announcement template for your staff; temporary access we were granted removed. Go-live is the end of week 3.
We review a month of transcripts, unanswered questions, escalation reasons and Copilot Credits consumption, add or adjust topics and knowledge, republish, and hand you a short report with the numbers and a prioritized backlog for your makers or for Managed AI Agent Operations.
Prerequisites
Who does what
IT Partner
- Analyse the ticket export, inventory the knowledge, confirm the licensing and Copilot Credits position, and write the design record for your sign-off.
- Build the agent from Microsoft's IT Helpdesk template: knowledge sources, the five request paths with diagnostic collection, the ITSM or help-desk hand-off, authentication and security settings.
- Run the scripted test set, operate the pilot, fix what it surfaces, and publish the agent to Teams through the Teams admin center.
- Capture the analytics baseline, deliver the maker handover and runbook, and remove any temporary access we were granted.
- Deliver the 30-day tuning pass and its written report.
Your team
- Provide the ticket export, access to the knowledge sources, the ITSM instance and integration credentials, and the Power Platform and Teams admin access the build needs.
- Name the product owner and the pilot group, and make design decisions within two business days so the three-week plan holds.
- Sign off the design record before build and the test results before publish.
- Hold the Microsoft licensing the design requires — Microsoft 365 Copilot seats, a Copilot Studio capacity pack or pay-as-you-go plan — and pay Microsoft for the Copilot Credits your users consume, and your ITSM vendor for its licensing.
- Own the agent, its knowledge and its topics after handover; extend it yourselves or contract Managed AI Agent Operations.
What's not included
Limitations & technical notes
Frequently asked questions
What does the agent actually do on day one?
It answers IT questions from your own knowledge with a link to the source, walks users through the five request paths you chose from your ticket data — typically password and MFA reset guidance, software requests, access requests and VPN, Wi-Fi and printer how-tos — collects the device name, operating system, error text and a screenshot, and files a complete ticket in your ITSM or with IT Partner's help desk when it cannot resolve the problem. Users can ask it for their ticket's status afterwards where the connector supports lookup. It runs inside Teams and, for licensed users, inside Microsoft 365 Copilot.
Why start from Microsoft's IT Helpdesk template instead of building from scratch?
Because the template already encodes the right conversation: answer from knowledge, escalate to a ticket when the answer is not there, let the user check status. Microsoft maintains it in Copilot Studio's template catalogue and it is built around ServiceNow out of the box. Starting there is what lets us fix the price at $6,950 and the timeline at three weeks — the work is grounding it in your knowledge, authoring your request paths and wiring your ticketing system, not inventing the shape. Anything that outgrows the template is our custom Copilot Studio agent development service.
Does it answer only from our documents, and does it respect permissions?
It answers from the three knowledge sources agreed at design — for example your SharePoint IT site, your policy library and selected public Microsoft support pages — and from the authored topics. SharePoint and OneDrive knowledge honours each user's own permissions, so someone without access to a restricted document cannot pull its contents through the chat; we test that explicitly with a pilot user. Files uploaded directly into the agent are visible to everyone who can use it, so sensitive material stays in SharePoint. We also configure the agent to say when it has no answer rather than improvise one.
Which ticketing systems can it hand off to?
One of ServiceNow, Jira Service Management (Cloud), Freshservice or Zendesk through its Power Platform connector, or Halo through its REST API, or an email hand-off into IT Partner's help desk. The template's native path is ServiceNow — knowledge base plus incident creation and status; for the others we keep the same conversation and swap the actions. Each system's connector sets what is possible: ServiceNow can file the ticket under the user's own identity, Freshservice files under an integration account with the requester in the ticket fields, and Jira must be the Cloud edition. A second ticketing system is a separately quoted addition.
We do not have a ticketing system. What then?
Two honest options. The agent can hand off by email into IT Partner's help desk — our ticketing system logs it, our engineers work it under the Remote Support Help Desk Service's terms, and our published first-response SLA applies. Or, if you keep the human tier in-house, the hand-off lands in a Microsoft 365 route we agree at design — a shared mailbox or a SharePoint list with Teams notifications — which is workable for small teams but is not an ITSM, and we will say so.
Can it reset passwords or fix MFA on its own?
No, and we would not build it that way. The agent guides the user through your approved self-service route — Microsoft Entra self-service password reset, MFA re-registration, your access-request process — and, where the route needs a human, files an authenticated request with the diagnostics attached for a technician to approve and execute. An agent that changes credentials or group membership unprompted is a security finding waiting to happen; anything privileged stays behind a person or an approval.
Do our users need Microsoft 365 Copilot licenses to use it?
No. Users who hold a Microsoft 365 Copilot seat are covered by it — Microsoft's licensing guide includes Copilot Studio agents for Teams, SharePoint and Microsoft 365 Copilot with the seat, so they are not metered. Everyone else uses the agent through Copilot Credits: a Copilot Studio capacity pack or pay-as-you-go against an Azure subscription in your tenant. That is Microsoft's charge, not ours; we confirm which applies to your user mix at kickoff, and for organizations that buy their Microsoft licensing through IT Partner we switch pay-as-you-go on at no charge.
How much will the Copilot Credits cost us?
It depends on how many unlicensed users ask how many questions, and how the agent answers them. At the time of writing Microsoft meters a generative answer at 2 credits, adds 10 when the answer is grounded in your tenant's Microsoft Graph content such as SharePoint, and charges 5 for an agent action; a credit is $0.01 pay-as-you-go or comes from a 25,000-credit pack at $200 per month. Authored topics are the cheapest interaction, which is one reason the five request paths are built that way. We estimate your monthly consumption from your ticket volumes and user mix at kickoff, set the alerts, and revisit the real number in the 30-day tuning pass — we do not print a figure before we have seen your data.
Where do users find it?
In Microsoft Teams, as an app you approve in the Teams admin center and make available to the pilot group and then to the audience you choose — pinned to the app bar through an app setup policy if you want it in front of everyone. Users with a Microsoft 365 Copilot seat also see it in Microsoft 365 Copilot's agent list. A website or SharePoint channel is possible but is not part of the fixed price.
What counts as a knowledge source, and what counts as a request path?
A knowledge source is one connected corpus: a SharePoint site or library, a set of policy documents, a public website such as Microsoft's support pages, or your ITSM's knowledge base. A request path is one authored conversation with its questions, diagnostic capture and hand-off — 'reset my password' is one, 'request software' is another. The fixed price covers up to three sources and up to five paths; more are quoted in writing before work starts; the limits are set for the 100-to-2,000-seat organizations this service is built for.
How do you measure whether it is working?
Copilot Studio's built-in analytics: sessions, engaged sessions, resolution rate, escalation rate, abandon rate, the unanswered-questions list and, where enabled, the user satisfaction prompt. We capture the baseline at go-live, and the 30-day tuning pass reports the month's numbers, what we changed and what remains in the backlog. We do not sell a deflection percentage; the analytics are yours to read and hold us to.
What happens after the 30-day tuning pass?
The agent is yours: your makers extend it with the runbook from the handover, adding knowledge sources and topics and republishing as your IT changes. If nobody on your team has the time, Managed AI Agent Operations and Optimization takes it over month to month — transcript review, knowledge refresh, credit watch and safety checks — at its own published price. There is no lock-in either way; the agent, the environment and the connections stay in your tenant.
Is it secure? Does any of our data leave the tenant?
The agent runs in a Power Platform environment in your Microsoft 365 tenant, authenticates users with Microsoft Entra ID, reads knowledge under the user's own permissions for SharePoint content, and talks to your ITSM through a connection you own. Nothing routes through IT Partner infrastructure, and the access we use to build it is granular, time-bound and removed at handover. Environment data-loss-prevention policies, generative-answer settings and content moderation are configured and documented. A formal review of the agent against your Purview and data-protection policies is a separate engagement we recommend once more than one agent is in production.
What exactly does the $6,950 include, and what changes it?
Everything on this page for one agent: ticket analysis and design, the template-based build with up to three knowledge sources and five request paths, one ticketing hand-off, Teams publishing, security configuration, the pilot, analytics baseline, the maker handover with runbook, and the 30-day tuning pass. Quoted fixed-price in writing before work begins; you pay after you approve delivery. A second ticketing system, more sources or paths, additional channels, a custom connector, or knowledge that has to be written before it can be read change the quote — in writing, before work starts. Copilot Credits, Copilot Studio licensing and ITSM licensing are the vendors' charges.
How long does it take?
Three weeks from kickoff to go-live when the environment, licensing, ITSM credentials and knowledge access are ready by day three: week one for analysis and design sign-off, week two for the build and pilot, week three for fixes, publishing and handover. The tuning pass follows about 30 days after go-live. Waiting on an OAuth registration in ServiceNow or a Teams app approval extends the calendar, not the price.
Can IT Partner also be the help desk behind the agent?
Yes. The agent hands off by email into our help desk with the diagnostics attached, our engineers work the ticket remotely under the Remote Support Help Desk Service — its own hourly terms, published on its page — held to the first-response SLA we publish for our help desk, one business hour, with monthly statistics on our verify page. Organizations that buy their Microsoft licensing through IT Partner already have unlimited break-fix support during business hours included, which is often the tier the agent escalates into.
Why should we trust you with a Teams app?
Because we ship one. Our own ITP Assistant Teams app is Microsoft 365 App Certified, with the attestation published on Microsoft's site, so the Teams admin-center approval, app setup policies, permission consent and the questions your security team will ask are things we answer routinely. We have been a Microsoft partner since 2006 and hold Solutions Partner designations you can verify in Microsoft's directory.