The connector step that used to ask why

An MCP server at general availability changes who has to agree before an agent touches your ERP. Microsoft's Dynamics 365 blog published a portfolio update on September 23, 2026 by Sameer Verma, whose byline on that post reads Vice President and Chief Product Officer of Microsoft Dynamics 365 AI ERP. The sentence that carries the weight: "The Dynamics 365 ERP plugin for Copilot Cowork and the Dynamics 365 ERP MCP server, both generally available, allow agents to reason over and work with ERP data, actions, and attachments."

The ordering inside that sentence is the story. Data, then actions, then attachments. Reasoning over ERP data was settled years ago for most finance teams. Working with ERP actions means an agent can invoke business logic that posts, approves and releases, and it can do that in the Dynamics 365 finance and operations apps without anyone building a custom connector first.

That missing connector used to be the work, and the work was an unplanned approval gate. Every earlier project where an agent reached into ERP had a developer in the middle who could ask why before writing the code. What disappears is the integration rather than the connector, along with the conversation attached to it. That person is now optional.

The matching access control is still in the future tense

The same post describes the matching control in careful wording: "New capabilities in role-based access controls will allow organizations to define additional restrictions when a user is operating through Copilot Cowork or agents, enabling tighter control on what agents are allowed to do." Will allow. The post never states that those restrictions are available today, and we will not read it as though it did.

So the capability is generally available and the constraint built for it is described as coming. That deserves saying plainly, with no alarm attached. Nothing has been breached and no finance system became open on September 23. What changed is that the integration effort which used to slow an agent project down has gone, while the access control written for agent behaviour has not.

Microsoft's roadmap for this portfolio runs through March 2027, so there is room to plan. The open question is what happens in the months between a plugin somebody can switch on and a restriction they cannot yet configure. Other vendors have hit the same ordering, and we covered ServiceNow putting its MCP actions behind existing governance earlier.

A permission set designed for human pace

An agent operating through a user's context inherits that user's permissions, and that floor is genuine rather than a technicality. Security roles, duties and privileges still apply at execution. If a clerk cannot post to the general ledger, an agent running inside that clerk's context cannot post either. Anyone claiming an MCP server walks past ERP security has not read how it authenticates.

The floor stops being sufficient for a reason unrelated to faulty software. A permission set gets designed around a person working at human speed. Someone with journal posting rights enters a few dozen lines on a busy day, and the shape of their attention forms part of the control even though nobody wrote it down. The same permission set, exercised by something that can call every action it is entitled to call within seconds, is a different quantity of exposure.

That is the argument for reading role definitions again rather than trusting role names. Most ERP estates carry roles that accumulated across two implementations and a reorganisation, and a segregation of duties review for people wearing four hats turns up combinations nobody intended to grant. Those were tolerable at the speed a human works.

Work out which roles Copilot Cowork can reach

The useful preparation has two parts, and neither waits on Microsoft shipping anything. Establish which security roles would be reachable through Copilot Cowork in your environment, then which posting and approval actions those roles can already perform today. Most teams find the second list longer than they assumed.

Begin with finance, because that is where the posting privileges sit. Anyone who can post a journal, release a payment run, approve a purchase requisition or amend vendor bank details holds a privilege that reads differently once an agent can invoke it. Note what each role can complete without a second approver, because that set is what an agent inherits on day one. Stories about an AI system posting to a general ledger turn on the approval path around it.

The journals work in the same post matters here. Finance journals have been re-engineered for higher transaction volumes and cross-legal-entity complexity, covering intercompany transactions, accruals and allocation previews before posting. A preview before posting is a control, and finding which of your journal types use one is better done before an agent starts generating entries at volume.

France e-invoicing landed on the same day

The quieter sentence is the one finance will care about most: "France e-invoicing and e-reporting support is also generally available, with support for the next phase of Brazil's tax reform on the roadmap." Compliance capability ships on the same cadence as agent capability, from the same product group, in the same update. A team with French entities has a statutory deadline attached to the first half of that sentence and none attached to anything agentic.

The rest of the update mixes the two the same way. Business Performance Planning demo data and a starter kit are generally available. Procurement agent impact analysis and Supplier Engagement are in public preview, demand planning generative insights have been generally available since August, and rental management is coming to public preview. Project Operations change order management and a Commerce MCP server are both in public preview, and sustainability data trails now run from snapshots with reporting-period locks.

Before anyone switches on the ERP plugin for Copilot Cowork outside a sandbox, run one report. Pull every security role assigned to the users who would receive it, then the posting and approval privileges those roles carry. Take the entries that surprise you to whoever signs off on financial controls, and settle which were acceptable only because a person had to click through them one at a time.