AI Pilot Service Limitations
AI Pilot applies approved fixes directly in your Microsoft 365 tenant through Microsoft Graph. Its remediation registry covers findings that map to a single, verifiable Graph write, so most failing controls are fixed automatically once you approve them.
A smaller set of controls is intentionally out of scope for automatic remediation. AI Pilot does not act on these on its own, because the change needs tenant-specific judgement, would delete live data, or lives on an admin surface Microsoft Graph does not expose. These controls are not hidden: they still appear in your scan results with full, step-by-step remediation instructions on each control's detail page. This page explains the categories and why each is handled manually.
AI Pilot remains automatic for everything in its remediation registry. The limitations below are deliberate safety boundaries, not gaps in coverage.
Conditional Access controls are not a limitation
Several high-impact controls (block legacy authentication, risk-based policies, phishing-resistant MFA, "at least one Conditional Access policy" coverage) are remediated by AI Pilot creating a Conditional Access policy rather than toggling a single setting. AI Pilot still handles these for you, from the Conditional Access section of the AI Pilot page. Every policy is created in report-only mode first so you can review its impact before enforcing. These are part of AI Pilot's automatic scope, not a limitation.
What AI Pilot does not auto-remediate
Privileged role assignments and PIM
Removing or reassigning an administrative role can lock an administrator out of the tenant, so AI Pilot never changes role assignments unattended. A person decides who keeps standing access, who approves privileged-role activation, and who receives the related alerts.
Affected areas include splitting privileged users onto finer-grained roles, removing permanent privileged assignments, provisioning roles through Privileged Identity Management (PIM), requiring approval to activate Global Administrator, and configuring alerts for privileged role assignments and activations.
Where to act: Microsoft Entra admin center, under Roles and Privileged Identity Management.
Control Plane role removals
Removing a standing Control Plane role from an external, hybrid (on-premises synced), or mailbox-enabled user needs a human to confirm the access is no longer required. A service principal that holds a client secret alongside a standing Control Plane role needs a person to rotate it to a safer credential and tighter scope.
Where to act: Microsoft Entra admin center, under Roles and Administrators.
Entitlement management hygiene
Repairs to access governance touch live data. AI Pilot does not delete or rewrite entitlement-management objects automatically. Fixing stale catalog roles, repairing access packages that reference deleted groups, resolving orphaned assignment policies, setting valid approvers, and deciding what to do with unused catalog resources each need a human review.
Where to act: Microsoft Entra admin center, under Identity Governance > Entitlement management.
Admin surfaces Microsoft Graph does not expose
Some settings live in product admin centers that Microsoft Graph does not expose to AI Pilot, so they cannot be written programmatically:
- External sharing limits in the SharePoint admin center.
- Restricting third-party storage providers in the Microsoft 365 / Office admin settings.
- The Teams meeting lobby policy in the Teams admin center.
Where to act: the relevant product admin center listed above.
Tenant-specific group and device curation
These changes depend on decisions that only your organization can make: which public groups are approved, the membership rule for a dynamic guest group, and which users or groups may join devices. AI Pilot does not guess tenant-specific policy.
Where to act: Microsoft Entra admin center, under Groups and Devices.
Guest invite domain allow-list
Restricting guest invitations to approved domains requires you to supply the domain allow-list in cross-tenant access settings. AI Pilot does not invent the list of trusted partner domains.
Where to act: Microsoft Entra admin center, under External Identities > Cross-tenant access settings.
Lockout-prone authentication methods
Enforcing FIDO2 security-key restrictions without an allow-list of approved keys can block every security-key sign-in. A person must choose the approved keys before this is enforced.
Where to act: Microsoft Entra admin center, under Authentication methods.
How to handle a limited control
- Open the failing control from your scan results.
- Follow the remediation steps on the control's detail page.
- Apply the change in the admin center named above.
- Re-run the scan to confirm the control now passes.
For everything inside AI Pilot's registry, approving the fix is enough. See the AI Pilot guide for the full remediation flow.