If you’ve built anything agentic against Business Central data, you know the drill: before an agent can touch a table, someone has to expose it as an API page first. No page, no access — full stop. Business Central 29.0 quietly changes that.
According to Microsoft’s official Update 29.0 preview overview, the MCP Server picks up new tools that let agents define, validate, and run their own data queries — explicitly for data that doesn’t have an existing API page yet. It’s listed as a single line item under “Copilot and agents” in the release notes, easy to miss next to the Expense Agent’s six-feature jump in the same update. But for anyone building BC integrations through MCP, it’s arguably the more structural change of the two.
The gap this actually closes
Up to now, getting an agent to read BC data meant one of two paths: an exposed API page, or Dynamic Tool Mode pulling from the set of pages someone already decided to expose. Either way, the bottleneck was the same — a human had to expose the page first, deliberately, as a separate step from whatever the agent actually needed to do. For a lot of scenarios that’s fine. For anything ad hoc — “can the agent check this one field on this one table nobody thought to expose” — it wasn’t, and building a one-off API page just to unblock a query was the kind of overhead that made a quick agentic idea not worth doing.
The new query tools remove that step. An agent can define a query directly, have it validated, and run it — without a page in between. That doesn’t replace API pages as the primary, governed access surface; it adds a second door for the cases that don’t justify one.
Where this sits next to what already exists

Worth being precise here, because “MCP” in a BC context covers more than one thing. This is the BC data MCP Server — the one built-in tenant agents and Copilot Studio flows talk to for actual business data. It’s a different server from the AL MCP Server, which is developer tooling for VS Code and also got upgrades in this same v29 preview (dynamic workspace configuration, file-based diagnostic logging, headless operation without authentication prompts). Don’t conflate the two when you’re scoping a project — one is for querying BC records, the other is for writing AL code.
What’s still open
Microsoft’s overview describes the capability in one sentence and doesn’t link a detail page covering the permission model, the query language or syntax agents use to define these queries, or where the practical limits sit — what counts as “data without an existing API,” whether there are table- or field-level restrictions, how this interacts with existing permission sets. All of it needs verification against the feature-detail documentation before this goes anywhere near a client environment, and the whole feature carries Preview status under Microsoft’s Supplemental Terms of Use — no GA date attached.
That’s not a reason to ignore the feature. It’s a reason to treat it as “confirmed direction, unconfirmed mechanics” for now. Business Central 29.0 as a whole reaches general availability in October 2026 — but Microsoft hasn’t said whether this specific query-tools capability leaves Preview on that date or later.
What to actually do with this now
If you’re building anything agentic against BC data, this is worth a sandbox session before GA — specifically to answer the permission-model question yourself, since the docs don’t. Try defining a query against a table that has no API page today, and check what governs whether the agent can see it: existing permission sets, something new, or nothing yet (which would be its own finding worth flagging to a client before go-live). Whatever you find, it changes how you’d pitch this to a client compared to the safer, already-governed API-page path.
Source
Sources: What’s New or Changed in Business Central 2026 release wave 2 – Update 29.0 preview, Microsoft Learn (ms.date 2026-09-07 as of live verification on 2026-09-15; this is prerelease documentation and continues to change). Configure Business Central MCP Server, Microsoft Learn (ms.date 2026-05-03), for the existing Dynamic Tool Mode access path referenced above.
Discover more from Lubenheimer
Subscribe to get the latest posts sent to your email.