Microsoft Agent 365
by Microsoft
The control plane for observing, governing and securing enterprise AI agents
Microsoft Agent 365 is a control plane that gives IT administrators a single registry, identity model and security perimeter for every AI agent running in an organisation — Microsoft-built, partner-built, or imported from Amazon Bedrock and Google Vertex AI. It reached general availability on 1 May 2026 and licenses at $15 per user per month, or bundled inside the new Microsoft 365 E7 suite.
Microsoft Agent 365 is Microsoft's management and governance layer for AI agents, organised around three pillars its documentation names explicitly: observe, govern and secure. Announced at Ignite 2025 and generally available for the Commercial segment on 1 May 2026, it treats agents as first-class enterprise identities rather than shadow software. Every agent receives a Microsoft Entra Agent ID and appears in a central registry in the Microsoft 365 admin center, alongside an Agent Map and role-specific reporting so security leaders and AI admins can see agent adoption, activity and health in one place. Governance covers lifecycle management, access control and compliance review through Entra and Microsoft Purview; security extends Purview information protection and DLP, plus Defender threat detection and real-time runtime blocking, to agent behaviour — so an agent only reaches resources it is authorised to reach. The pitch is deliberately cross-vendor: 23 pre-integrated ecosystem partners shipped at launch, split between ready-to-deploy agents (Box, Canva, Figma, Miro, Zendesk, Zoho, Sophos, Coursera, Cornerstone, Achievers, Gloat, Lucid, Rox, Genspark, Manus, Egnyte, Zensai, Adobe) and "agent factories" — Kore, Kasisto, n8n and NVIDIA NeMo — whose agents are automatically provisioned with an Entra Agent ID at creation and inherit the same identity, compliance and observability controls. Agents already built on Google Vertex AI or Amazon Bedrock can be registered into the admin center with no development work. Microsoft has since added discovery of locally running agents on Windows endpoints, with initial support for OpenClaw platform agents and a roadmap covering GitHub Copilot CLI and Claude Code. Microsoft states the product "works best when using Microsoft E5 as a pre-requisite," and at least one user must hold a qualifying licence to enable it for a tenant.
CISOs and M365 platform owners in Microsoft 365 E5 tenants who already run Entra, Purview and Defender and now need an inventory and policy perimeter for agents business teams deployed without them.
Every agent in the tenant gets a directory identity, an audit trail and the same DLP and threat-protection policies as a human user — without standing up a new security stack.
At a Glance
- Category
- Governance & Security
- Pricing
- Subscription, Contact for pricing
- Target Market
- CISOs, CIOs, IT Administrators, Enterprise Architects, Compliance and Risk Leaders
- Deployment
- Cloud-only, Multi-cloud
- Founded
- 1975
- Headquarters
- Redmond, Washington, United States
- Team Size
- 500+
Key Features
- ✓Agent registry
A single centralised inventory of every agent in the tenant, viewable and manageable from the Microsoft 365 admin center.
- ✓Entra Agent ID
Gives each agent a first-class directory identity so access control, lifecycle and reviews work exactly as they do for employees.
- ✓Agent Map and observability dashboard
Visualises agent relationships, adoption and activity with role-specific views tailored for security and business leaders.
- ✓Purview data protection for agents
Extends information protection, DLP and risk safeguards to what agents read and write, not just what users do.
- ✓Defender runtime protection
Continuously detects threats and blocks unsafe agent behaviour in real time while the agent is executing.
- ✓Ecosystem partner integrations
23 pre-integrated partners at launch, including agent factories whose output inherits Agent 365 governance automatically at creation.
- ✓Registry sync for AWS and Google agents
Surfaces agents already built on Amazon Bedrock or Google Vertex AI in the admin center with no development work required.
Capabilities
Use Cases
- •Agent inventory and shadow-AI discovery
Find every agent running in the tenant, including local agents on Windows endpoints, before an auditor or an incident does.
- •Least-privilege access for agents
Apply Entra risk-based conditional access so an agent acting for a user can never exceed that user's own entitlements.
- •DLP enforcement on agent output
Stop an agent surfacing regulated data into a Teams chat by extending existing Purview policies to cover agent actions.
- •Governed rollout of partner agents
Deploy Box, Zendesk or Sophos agents from the admin center with full activity tracking instead of ad-hoc per-team installs.
- •Agent ROI and process measurement
Feed Agent 365 activity into Celonis process intelligence to tie specific agent actions to cost-per-claim and cycle-time outcomes.
Ideal For
Best For
- ✓Microsoft 365 E5 shops that already run Entra, Purview and Defender and want agents governed inside the same control plane
- ✓CISOs who need a defensible inventory and audit trail for agents deployed without IT involvement
- ✓Organisations standardising on a single agent identity model across Microsoft, partner and third-party platforms
- ✓Enterprises adopting partner agent factories — Kore, Kasisto, n8n, NVIDIA NeMo — that want governance applied automatically at agent creation
- ✓Regulated industries needing DLP and real-time runtime blocking applied to agent actions, not only to user actions
Not Ideal For
- ✗Organisations not standardised on Microsoft 365 — the documentation states Agent 365 'works best when using Microsoft E5 as a pre-requisite,' so most of the value collapses outside that stack
- ✗AWS Bedrock or Google Vertex AI shops: as one independent review put it, they 'have little reason to accept Microsoft as the cross-vendor control plane on the strength of registry import alone'
- ✗Small teams running a handful of agents, where a per-user charge across the whole tenant is hard to justify against actual agent sprawl
- ✗Buyers who need complete governance today — third-party agents not onboarded through the Agent 365 SDK cannot be governed at the agent identity level, and shadow agents can still run
Integrations
Deployment
Market Analysis
Pros
- ✓Reuses controls enterprises already own — Entra, Purview, Defender, Intune — so there is no parallel security stack to buy, staff or operate
- ✓Genuinely cross-vendor at the registry level: agents built on Amazon Bedrock or Google Vertex AI can be surfaced with no development work
- ✓23 pre-integrated partners at GA, including agent factories (Kore, Kasisto, n8n, NVIDIA NeMo) that provision an Entra Agent ID automatically
- ✓Extends to locally running agents on Windows endpoints, which is where most genuinely ungoverned agent activity currently sits
Cons
- ✗Per-user pricing on top of a recommended E5 prerequisite makes cost scale with headcount rather than with agents; one independent review notes value 'will turn on how prevalent unmanaged local agents actually are on a given fleet'
- ✗The agent-sprawl premise driving the purchase is, in that same independent assessment, 'Microsoft's own vendor positioning and lacks independent confirmation'
- ✗Cross-cloud support is shallow — registry import only — so AWS and Google customers have little reason to cede the control plane on that basis
- ✗Governance is incomplete at GA: an independent licensing analysis notes shadow agents can still run, third-party agents not onboarded via the Agent 365 SDK cannot be governed at the identity level, and policy-based lifecycle cleanup is 'planned and will roll out incrementally'
- ✗Several headline integrations (Adobe, Celonis, Egnyte, Manus, NVIDIA) were still marked 'coming soon' as of July 2026, and AI teammate deployments remain limited to Frontier program participants
Pricing
Agent 365 (standalone add-on)
$15 per user per month
- ✓Per-user licensing
- ✓Agent registry, Agent Map and observability
- ✓Entra Agent ID
- ✓Purview and Defender agent controls
Microsoft 365 E7
Contact for pricing
- ✓Bundles Microsoft 365 E5, Microsoft 365 Copilot, the Microsoft Entra Suite and Agent 365
- ✓Generally available 1 May 2026
Licensed per user, not per agent: $15 per user per month as a standalone add-on, or bundled into the new Microsoft 365 E7 suite alongside Microsoft 365 E5, Microsoft 365 Copilot and the Entra Suite. At least one user must hold a qualifying licence to enable Agent 365 for a tenant, and Microsoft states it works best with Microsoft 365 E5 as a prerequisite — so the real cost for most buyers is E5 plus Agent 365, not $15 alone. Managing local agents on Windows endpoints adds further requirements: an Intune licence and an active Azure subscription for the Windows 365 for Agents Cloud PC tier. One independent licensing analysis also notes that as of 1 July 2026 Defender agent protection that was previously free now requires Agent 365 licensing.
Security & Compliance
Sources
This page was written from 5 sources, 4 on domains other than microsoft.com.
- 1.learn.microsoft.com — overview
- 2.learn.microsoft.com — third party agents
- 3.winbuzzer.com — microsoft agent 365 general availability local ai agents xcx
- 4.schneider.im — microsoft agent 365 control plane for ai agents
- 5.microsoft.com — microsoft agent 365 now generally available expands capabilivendor
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
OpenAI Daybreak
Vetted-access frontier AI for cyber defenders, with a purpose-built offensive-security model
NVIDIA OpenShell
Open-source, kernel-isolated sandbox runtime for autonomous AI agents
Zenity
Runtime AI agent security that blocks a harmful agent action before it executes
Saviynt Zuma
Identity control plane for AI agents and non-human identities, with runtime authorization