Back to Blog
Last updated Aug 06, 2026.

Dynamics 365's ERP Now Talks Back, and Writes Back. Copilot Cowork Is the New Front Door to Finance and Operations.

6 minutes read
Ali Ahmed

Ali Ahmed

AI Business Analyst & Product Owner, Cognilium AI

Share:
Dynamics 365's ERP Now Talks Back, and Writes Back. Copilot Cowork Is the New Front Door to Finance and Operations.
TL;DR

Microsoft has made the Dynamics 365 ERP apps plugin for Copilot Cowork generally available. An agent can read your finance and operations data in plain English, drive the forms, and with your approval create the purchase order. The interface problem is solved. The interesting question is what decision it should be executing.

Microsoft made the Dynamics 365 ERP apps plugin for Copilot Cowork generally available on 16 June 2026. An agent can now read finance and operations data, drive the forms, and with human approval write to the system of record. The interface is solved; the intelligence that decides is the next layer.
Dynamics 365Copilot CoworkModel Context ProtocolAI agentsFinance and OperationsAgentic ERPERP

Quietly, on 16 June 2026, Microsoft shipped one of the more consequential things to happen to ERP in years. The Dynamics 365 ERP apps plugin for Copilot Cowork went generally available. Copilot Cowork is an agentic orchestrator, meaning it strings multi-step work across systems, and this plugin connects it straight into your Finance and Operations environment through the Dynamics 365 ERP MCP server. If MCP was the doorway, this is someone actually walking through it and starting to do the job.

What actually shipped

Per Microsoft's own documentation the plugin hands the agent three classes of tools against live ERP data. Data tools read, create, update and delete records in finance and operations entities. Form tools navigate application pages, set field values and take actions exactly as a user would in the interface. Action tools invoke custom business logic a developer has exposed. Alongside those, Cowork brings its own Work IQ reach into email, calendar, documents and spreadsheets. So it is not a chatbot bolted onto a dashboard. It is one conversation that spans the ERP and the inbox at once.

The scenario that shows the point

Microsoft's flagship example is a sourcing manager evaluating a request for quote. A single prompt, evaluate bids for RFQ 000012, use the latest vendor emails and PDF attachments, update the replies in finance and operations, score the bids against the configured criteria and recommend the supplier to award, sets off the whole chain:

1. It pulls the RFQ lines, vendors and scoring criteria out of Dynamics 365 through the MCP server.

2. It reads the vendor bid emails and PDF attachments from Outlook.

3. It extracts and cross-references the bid details, flagging discrepancies between them.

4. It scores every response against the criteria already configured in the ERP.

5. It generates a recommendation document with ranked vendors, strengths and risks.

6. On your approval it creates the purchase order in Dynamics 365 and drafts the award email.

Read that last step again. The agent does not just summarize. It writes to the system of record. That is the line ERP vendors spent years refusing to cross, and it is now crossed inside a mainstream product.

The guardrails, because writing to the ERP is the scary part

Microsoft draws the fence carefully. Every write operation requires explicit human approval. The agent shows you what it intends to change and waits. Access runs entirely through the acting user's security roles, so the agent can never read or touch anything the person could not already touch in the app. It requires Finance and Operations version 10.0.45 or later, and the MCP server is not supported on Cloud Hosted Environments. This is the same governance instinct worth taking seriously everywhere agents meet enterprise data. The subtle danger is not a wrong answer, it is an agent silently joining records that were never meant to connect.

The part most coverage misses

Here is the strategic read. Microsoft just solved the interface to the ERP. You can now talk to Finance and Operations, and it can act. But an interface is not intelligence. Knowing how to ask the warehouse a question is different from knowing which question is worth asking: which SKUs should move closer to the pick face, how to slot for the season, where the pick path is quietly costing you steps. That decision layer sits on top of the exact same finance and operations data this plugin now exposes, grounded and structured and queryable, which is the reason structured retrieval is becoming the 2026 default. The front door is open. What matters next is what you send through it, which is precisely the layer an optimization engine like Cognilium is built to be: the intelligence that decides, riding on the interface Microsoft just standardized.

Share this article

Share:

Weekly AI engineering brief

One email a week. New model releases, agent patterns, and lessons from production systems we ship.

No spam, no client data sales. Unsubscribe any time.

Ali Ahmed

Ali Ahmed

AI Business Analyst & Product Owner, Cognilium AI

Ali Ahmed is an AI Business Analyst and Product Owner at Cognilium AI, where he owns the product…