TL;DR
What Microsoft documents the Payables Agent can and cannot do, taken from its own pages, including where a person still has to approve the work.
Microsoft publishes them as a list, and it is short. PDF attachments only · ten per email · no PDF over ten pages or five megabytes · daily caps on emails and invoices. Two whole capabilities are named as unsupported. That list decides whether the agent fits your accounts payable — before any configuration question does.
What actually gets through to the agent?
Six constraints, all from Microsoft's own limitations section:
| Constraint | Microsoft's words |
|---|---|
| File type | "The agent only processes emails with PDF attachments" |
| Attachments per email | "skips emails with more than 10 attachments" |
| Page count | "doesn't process PDFs with more than 10 pages" |
| File size | "doesn't process PDFs larger than 5 MB" |
| Daily email volume | "doesn't process more than 100 emails per day" |
| Daily invoice volume | "doesn't process more than 500 invoices per day" |
Emails without a PDF are not silently dropped. Microsoft: they "are not processed for invoice creation" and "appear as agent tasks that require manual attention." So the work still arrives — it arrives as a task for a person.
The attachment cap has a sharp edge worth knowing. An email with eleven attachments is not partly processed. "The agent skips emails with more than 10 attachments" — the whole email, not the eleventh file. A supplier who batches a month of invoices into one message hits this immediately.
And each PDF becomes its own unit of work: "Each PDF document found in an email becomes an entry in Inbound E-Documents… A distinct agent task processes each entry." That is also why the per-document metering works the way it does — the event breakdown is published per document.
What does the agent refuse to do?
*Two capabilities, named by Microsoft under its own Feature limitations heading:*
Approval flows · Anomaly detection
This is a published limitation list, not a search that found nothing — which is the strongest form this kind of claim takes.
Both absences matter more than they read. An accounts payable process without approval routing is not an accounts payable process in most organisations, so the approval step has to live somewhere else — Business Central's own workflow engine, with its own events and responses. And anomaly detection is the control most people assume an AI feature includes: the agent extracts and matches, it does not flag the invoice that is subtly wrong.
The agent also does not post. Microsoft's flow ends at a purchase invoice — the drafts are reviewed "so invoices are ready for approval and posting." Ready for, not posted.
Where does it stop and hand back?
At the vendor, and the stop is deliberate.
If it cannot identify the vendor confidently, the agent halts and asks a supervisor. A supervisor can instruct it to create the vendor from the extracted details — and Microsoft is careful about what happens next:
"When the agent creates a new vendor, the Blocked field on the vendor card is set to All… leaving the newly created vendor in a blocked state ensures no invoicing processing can happen until the vendor is unblocked."
And it says plainly why: "vendors and their bank accounts are approved by having communication with the vendor and doing human callbacks to the vendor's finance department. In many places, this action is a requirement for a successful audit."
Read that as a design principle, not a quirk. Counterparty-supplied data is not trusted by default. The agent will create the record and then refuse to let it transact until a person has done something outside the system.
Microsoft states the boundary flatly: "The agent itself doesn't provide any capabilities for vendor approvals."
Why does the mailbox setup matter so much?
Because the mailbox is the trust boundary, and Microsoft treats it that way.
"We recommend you use a shared mailbox that you keep as an internal-only mailbox and don't expose this mailbox to your vendors… by not exposing invoices to vendors, your employees become the first to review and identify potential fraud."
Three operational rules follow, all published:
- "The monitored mailbox should only be attended from within Business Central."
- "Users shouldn't access the monitored mailbox from Outlook."
- Do not share it with another agent — "If other agents, like the Sales Order Agent, use the same mailbox, it can cause conflicts with ownership of incoming emails."
The second rule is the one that breaks quietly in practice. An email a person has already opened in Outlook is an email the dispatcher may not pick up — and nothing tells you the invoice was missed, because from the agent's side nothing happened.
So does it fit your accounts payable?
Answer four questions about your own mail, in this order, before anything else:
- Do your suppliers send PDFs? If a meaningful share send links, portals or spreadsheets, those invoices arrive as manual tasks regardless of how the agent is configured.
- How long is a typical invoice? The page cap is the limit most likely to bite a construction, logistics or professional-services supplier with itemised backup.
- Does anyone batch? One supplier attaching a month of invoices to a single email is skipped entirely.
- Where does approval live today? It cannot live in the agent, so it has to live in a workflow, and that is a separate design decision.
Those four answers decide fit. Everything else — permissions, profiles, supervisors — is configuration, and configuration only matters once the documents can actually get through.
And the limits are worth reading as a family rather than one at a time. Where all the built-in agents stop is the same exercise across Sales Order, Payables and Expense, and the pattern is more useful than any single cap.
About Cognilium Cognilium builds AI optimization apps for Microsoft Dynamics 365 — companion apps that optimize the pricing, inventory, warehouse and planning decisions your ERP manages but can't optimize. Dynamics is your system of record. Cognilium is your system of intelligence. https://cognilium.ai · https://www.linkedin.com/company/37180269/
Agentic ERP. We build turnkey AI optimization apps for Dynamics 365 — sidecar applications that run in your own Azure tenancy and solve the calculations a standard ERP is not built to compute. Built on Azure OpenAI, Microsoft Fabric and Copilot Studio. We build these on request, against your data and your environment.
More on the boundary between what Copilot does and what you build: Agentic ERP on Dynamics 365.
Run the four questions above against one month of your own supplier mail. Bring the answers to a 15-minute call and we will tell you where the agent fits and where it does not.
Sources
- Payables Agent Overview — Business Central ·
ms.date2026-05-03, updated 2026-07-08
Sources and fact-check
| # | § | Claim | Tier | Primary source | Verdict |
|---|---|---|---|---|---|
| 1 | 1 | Six document and usage constraints, quoted individually | T1 — verbatim ×6 | payables-agent, Limitations, verified against raw page source 2026-09-10 and re-read 2026-09-15 | PASS — load-bearing |
| 2 | 1 | Emails without PDFs "are not processed for invoice creation" and "appear as agent tasks that require manual attention" | T1 — verbatim ×2 | Same page | PASS |
| 3 | 1 | The attachment cap skips the whole email | T1 — verbatim, "skips emails with more than 10 attachments" | Same page | PASS — the word is emails, not attachments |
| 4 | 1 | Each PDF becomes an Inbound E-Documents entry with a distinct task | T1 — verbatim, form name character-exact | Same page | PASS |
| 5 | 2 | "Approval flows" and "Anomaly detection" listed under Feature limitations | T1 — verbatim | Same page | PASS — a published absence, quoted |
| 6 | 2 | Drafts are finalised "so invoices are ready for approval and posting" | T1 — verbatim | Same page | PASS |
| 7 | 3 | New vendor gets Blocked = All; the stated audit rationale; human callbacks | T1 — verbatim ×2 | Same page, Note | PASS |
| 8 | 3 | "The agent itself doesn't provide any capabilities for vendor approvals" | T1 — verbatim | Same page | PASS |
| 9 | 4 | Shared internal mailbox recommended, with the fraud rationale | T1 — verbatim | Same page | PASS |
| 10 | 4 | Attend only from within Business Central; not from Outlook; agent-conflict warning | T1 — verbatim ×3 | Same page, Caution and Note | PASS |
| 11 | 4 | A read email may not be picked up, and nothing reports it | T2 — ours, reasoned from claims 9 and 10, marked as ours | — | PASS — not attributed to Microsoft |
| 12 | 5 | The four fit questions | T2 — ours, method | — | PASS |
| 13 | 5 | "the limit most likely to bite a construction, logistics or professional-services supplier" | T2 — ours, a judgement about document length, no figure and no study claimed | — | PASS — opinion, labelled |
Tier summary: 11 × T1 (all verbatim), 2 × T2 — 0 × T4.
🔴 No pricing anywhere in this article, per the founder ruling of 2026-09-15. The credit consumption for these documents is a separate article and carries no currency figure either. This piece is about what the agent will and will not accept.
The absences here are Microsoft's own. "Approval flows" and "Anomaly detection" sit under Microsoft's Feature limitations heading. We are quoting a published limitation list rather than reporting a search that found nothing — the strongest form an absence claim takes, and the reason this article needs no bounding statement for them.
Status. The Payables Agent overview carries no preview banner and is not described as preview here. The Expense Agent is preview and is not discussed in this article.
No figures of ours. Every number is a Microsoft published constraint, quoted. No digits appear in either lifted block — the caps are described there in words.
Share this article
What Microsoft ships, what it does not, and the layer we build where a general assistant runs out.
