Morten Laske AI × Business Central
← Writing

Business Central 28.2: everything that shipped and the line you shouldn't skip

Business Central 28.2: everything that shipped and the line you shouldn't skip

Update 28.2 (June 2026) looks like a calm monthly drop: a tidy feature table, a few previews, "no localization updates." Easy to skim and move on. But one line sits under good to know, not in the feature table and it matters more than anything in the grid. So this is the whole release, grouped and with a verdict on each part and then a proper look at the line you shouldn't skip.

One scheduling note before the contents: Microsoft paused the 28.2 rollout for a stretch and has since resumed it, so it's landing on tenants now. If you postponed it or just hadn't seen it yet, it's on its way.

If you only have thirty seconds: most of 28.2 is solid, incremental and safe to adopt. The one thing to act on before July 1, 2026 is data residency for Copilot and agents. Now the detail.

Copilot and agents

This is where 28.2 is busiest and it splits into shipped features and preview platform plumbing.

  • Sales Order Agent in Belgium and Switzerland (GA). The agent expands to two more markets. The interesting part is why it needed help to get there: a new admin setting configures the text search language for multilingual environments, so the agent matches items correctly regardless of the data's language. If you run multilingual item data, that setting is the difference between the agent finding the right item and quietly picking the wrong one.
  • Cleaner email handling (GA). The Sales Order Agent now detects and skips inline attachments (signature logos, tracking pixels, embedded images) and reads only the real documents (PDFs, spreadsheets). Microsoft notes it also uses fewer credits, which is the honest headline: less noise in, less you pay per run.
  • Change AI models for agents (preview). Agents can now run on different AI models: pin a specific one per agent, or let automatic selection choose. Worth flagging because the model an agent runs on changes its behavior and results; "automatic" is convenient until an agent's output shifts and you can't say which brain produced last week's number. For anything load-bearing, this is a knob you'll want to set deliberately.
  • Evaluation framework. A way to test and validate Copilot and agent behavior in BC. This is the grown-up tooling the agent story was missing. If you build on agents, this is how you stop shipping on vibes.
  • In-product feedback (thumbs up/down). Now across most Copilot and agent surfaces plus the Shopify connector and Quality Management. Small, but it's the channel that shapes what Microsoft fixes next.

The line you shouldn't skip: where Copilot actually processes your data

Here's the good to know note in full: beginning July 1, 2026, environments on version 28.0 or later in some countries and regions might process Copilot and agent requests in a different Azure geography. For a partner who has been telling customers "your data stays in your region," that is the most important sentence in the release.

The confusion comes from collapsing two independent facts:

  • Where your data lives: the Azure region your environment's database sits in. Fixed at environment creation, visible in the admin center, unchangeable. A Danish environment lives in Europe North and stays there.
  • Where the AI thinks: the Azure OpenAI geography that processes the prompt. Copilot needs Azure OpenAI Service, which only runs in specific regions, not necessarily yours.

These are not the same place and nothing forces them to be.

where your data lives, your environment's Azure region
BC environment + databasestays in-region · never moves
prompt + output (may include personal data)
the gate, Copilot & agent capabilities Allow data movement ships ON · org-wide · off = no Copilot at all
crosses the boundary
where the AI thinks, Azure OpenAI geography
Azure OpenAI endpointEU env → stays in EU boundary · UK/AU/India/Asia agents → out, often the US
Two different places. Your business data stays pinned to its Azure region. The prompt and its answer leave through one org-wide gate that ships ON and from July 1, 2026 several regions' agent traffic is processed in another geography (the US for many). Where your data lives is not where the AI thinks.

What actually crosses depends on the region and Copilot and agents can route differently:

  • EU Data Boundary (West/North Europe, France, Germany, Norway, Sweden, Switzerland): AI processing stays inside the EU boundary. The defensible answer for most EU customers.
  • United Kingdom: Copilot stays local, but agent features process within the EU Data Boundary.
  • Australia and India: Copilot stays local; agents process in the United States.
  • Asia, Brazil, Canada, Japan, Korea, South Africa, UAE: United States.
  • United States: no movement.

And the control is one Allow data movement toggle on the Copilot & agent capabilities page and it ships on by default. Turning it off doesn't keep the AI in-region; it disables Copilot for the whole organization. The only fine-grained move is the reverse: leave it on and deactivate agent features individually. A consent that defaults to granted and can only be revoked by losing the feature is exactly what gets switched on in a demo and never revisited.

The five-minute check that belongs in onboarding, not your incident review:

  1. Admin center, the environment, Azure Region. Where the data lives. Write it down.
  2. Copilot & agent capabilities, Allow data movement. The gate. It's on.
  3. Map the region above: do Copilot and agent prompts stay in-region, stay in the EU boundary, or land in the US?
  4. Hold that against what you promised on residency and what the customer's regulators expect. "Agent traffic to the US" is a sentence a customer should hear from you on purpose, not discover.

Financial management

Three solid, real-world additions:

  • Withholding taxes for vendors (GA). Native vendor withholding-tax calculation, a recurring localization pain that's now in the box.
  • Self-billed invoices (GA). First-class support for the buyer-issues-the-invoice flow, common in scrap, agriculture and subcontracting.
  • Accelerated depreciation methods for fixed assets (preview). More depreciation models for FA. Still preview, so pilot it before you promise a client their year-end numbers depend on it.

Electronic documents

  • Payments in the E-Document framework (preview). The e-document framework grows from documents into payments. For anyone building on E-Documents, it's the direction of travel worth tracking.

Reporting and data: three new APIs with a theme

28.2 adds three GA APIs and the theme is governance and auditability:

  • Approval-workflow analysis API: for auditors and IT to inspect approval flows.
  • Permissions analysis API: for auditors and IT to inspect who can do what.
  • Document-report PDF API: fetch the PDF of a document report programmatically.

The first two are a clear signal: Microsoft is making BC's control surface queryable from outside, which is good news if you've ever assembled an access review by hand. The PDF API quietly removes a classic integration hack (driving the client to "print" a report).

Supply chain: Quality Management grows up

  • Word layouts as default (GA) for the three printable quality reports (Certificate of Analysis, Non-Conformance, General Purpose Inspection), with RDLC still available. Word-first means business users can actually edit the layout.
  • Demo data + role-center checklist (GA). An Install Demo Data action (Contoso Coffee) and a Quality Manager checklist that registers on first sign-in. This is the underrated one for partners: a guided path makes Quality Management demoable in minutes instead of an afternoon of setup.

Sustainability and governance

  • Sustainability, new integration APIs (GA). More surface to pull ESG data in and out.
  • Reimplementation via the cloud migration tool (preview). Run reimplementation projects through the cloud migration tooling. Relevant if you do migrations, still preview.

What to actually do with 28.2

Most of this is the good kind of release: incremental, GA, low-risk. Adopt the Sales Order Agent improvements, the financial-management features where they fit and put the new auditor APIs on your radar for your next access-review project. Pilot the accelerated-depreciation preview before you commit a client to it. (28.2 also carries the usual regional regulatory localizations in passing: Australian Payment Times reporting, UK Payment Practices, French e-invoicing in preview, relevant only if you have customers in those markets.)

But do the data-residency check this week. The features above are opt-in and visible; the data-movement default is opt-out and invisible and it has a date on it.

Business Central guarantees where your data lives. It does not guarantee where your AI thinks. From July 1, 2026, for several regions, the two are different places. Everything else in 28.2 you can adopt on your schedule. That one you adopt on Microsoft's.

Found this useful? Share on LinkedIn · email me a correction or follow-up.

Related