What Is Agent 365 and Why Enterprises Can’t Afford to Wait

 

AI agents are already inside your organization.

Some were deployed intentionally by your development team. Others were created organically by business users inside Microsoft 365. Some were procured through third-party software vendors whose platforms ship with agents already running.

Many of them have no defined owner, no documented permissions, and no governance framework describing what they can access or what they are authorized to do.

This is the reality that Microsoft Agent 365 was built to address.

Unveiled at Microsoft Ignite in November 2025 and generally available as of May 1, 2026, Microsoft Agent 365 is a centralized control plane for observing, governing, and securing AI agents across the enterprise. It gives IT administrators, security teams, and business leaders a single place to see every agent in their environment: what it does, what it can access, who owns it, and whether it is behaving within defined boundaries.

In just two months of preview operation, tens of millions of agents appeared in the Agent 365 Registry. That number reflects the scale of agent proliferation already underway across enterprise Microsoft 365 environments, not projected adoption, but agents already active.

“The agent conversation in most organizations is still happening in IT as a future-tense discussion. The agents are already there. The question is whether you have visibility into them and the controls in place to govern what they can do. Agent 365 is where that conversation starts getting resolved.”

— Jorge Zelaya, CISO, Atmosera

The urgency is not hypothetical. A KPMG AI Quarterly Pulse Survey from September 2025, covering 130 US C-suite leaders at organizations with $1 billion or more in revenue, found that 42% of large organizations have already deployed agents, 76% of leaders expect employees to be managing agents within two to three years, and 78% are concerned about cybersecurity for agents. Agent deployment is outpacing governance and the risk gap created by that lag is real.

Agent 365 is Microsoft’s answer to closing it.

 

The Agent 365 Control Plane: One View Across Your Entire Agent Fleet

The defining characteristic of Agent 365 is its scope. According to the official Microsoft 365 Blog announcement, the platform governs agents regardless of where they were built: Microsoft platforms, open-source frameworks, or third-party tools from vendors such as Adobe, Databricks, ServiceNow, and SAP.

That scope is what differentiates the Agent 365 control plane from narrower governance tools. Most organizations running Microsoft environments have agents built in multiple ways: through Copilot Studio, through Azure AI Foundry, through third-party SaaS products, and increasingly through multicloud platforms including AWS Bedrock and Google Cloud.

Without a unified control plane, each of these creates a separate governance domain with its own visibility gaps.

Agent 365 consolidates that view. The platform operates through five core capabilities:

  • Registry: A single, unified source of truth for every agent in the organization. Powered by Microsoft Entra Agent ID, the registry provides a comprehensive inventory including agent ownership, deployment platform, permissions, and policy alignment.
  • Access Control: Identity and access governance for agents, managed through Microsoft Entra. Agents receive their own identities, subject to the same access control policies that govern human users.
  • Visualization and Dashboard: Unified observability through telemetry, dashboards, and real-time alerts. IT leaders can monitor agent activity, behavior, and performance across the entire fleet from a single interface.
  • Interoperability: Support for agents built across Microsoft platforms, third-party tools, and multicloud environments. The Microsoft Agent 365 multicloud Registry Sync feature entered public preview on May 1, 2026.
  • Security: Threat detection and data protection through native integration with Microsoft Defender and Microsoft Purview, operating within the security infrastructure organizations already have in place.

All of this is accessible directly from the Microsoft 365 Admin Center, not a separate portal, not an add-on console. The Agent 365 control plane is embedded in the administrative environment that IT teams already operate in.

Learn how you can further safeguard your enterprise’s infrastructure, data, and more:

 

Agent 365 Architecture: How Microsoft Entra, Purview, and Defender Work Together

Understanding the Agent 365 architecture means understanding how it maps to the Microsoft security stack. Agent 365 is not a standalone security product. It is a governance and observability layer that extends the capabilities of Entra, Purview, and Defender to cover AI agents, entities that were not accounted for in traditional identity and access frameworks.

As described in the Microsoft Learn Agent 365 overview, the architecture operates across three integrated pillars: observe, govern, and secure.

Microsoft Entra: Identity for Every Agent

Every agent registered in Agent 365 receives a Microsoft Entra Agent ID. This gives each agent a verifiable identity within your organization’s identity infrastructure, subject to the same conditional access policies, permission boundaries, and lifecycle management workflows that apply to human identities.

This is a significant architectural shift. Until now, most agents operated without a formal identity in the organizational sense; they acted on behalf of users or applications without their own discrete access controls. Entra Agent ID changes that. Agents can now be granted specific permissions, have those permissions reviewed and revoked, and be tied to an accountable human owner within the organizational structure.

When an employee leaves, their sponsored agents can be automatically reassigned or decommissioned. When an agent’s purpose ends, its access is revoked like any other identity offboarding workflow.

Microsoft Purview: Data Protection for Agent Interactions

IDC projects that there will be 1.3 billion AI agents by 2028. Agents interact with data. They read documents, process emails, access SharePoint libraries, and query business systems. Without data governance controls, agent interactions create new vectors for sensitive data to flow in ways that no DLP policy was designed to catch.

Agent 365 extends Microsoft Purview capabilities to agent activity. Sensitivity labels govern what data agents can access. DLP policies apply to agent-generated outputs and agent-to-human interactions. Purview eDiscovery can place agent interactions under legal hold. Insider risk management monitors agent behavior for signals that indicate unusual or risky data access patterns.

The integration is built on OpenTelemetry standards, capturing detailed telemetry: AI usage events, tool usage, and notifications, and routing it to Purview for compliance processing alongside the Agent 365 dashboard for operational visibility.

Microsoft Defender: Runtime Threat Detection

1,500 AI attack vectors are tied to MITRE Atlas alone. The Defender layer adds real-time threat detection and posture management for agents in operation. This covers security posture assessment for agents, runtime blocking of unsafe behaviors, and detection of compromised or maliciously manipulated agent activity.

Agents are particularly vulnerable to a category of attack called prompt injection, where malicious instructions embedded in data that an agent processes cause it to take unintended or harmful actions.

Defender’s runtime monitoring is designed to detect behavioral anomalies that indicate this type of manipulation, as well as more conventional threats such as agents attempting to access resources outside their defined scope.
 

Agent 365 Security: Governing Identities That Are Not Human

Agent 365 Security Overview
 

The central security challenge with AI agents is that they behave like identities without being governed like identities.

An agent that has access to a user’s email, calendar, SharePoint files, and CRM data is holding delegated access that, in the wrong hands or under malicious manipulation, could cause significant harm. But until recently, that access lived in the background, granted informally, rarely audited, and entirely absent from the identity governance workflows that covered human accounts.

The Microsoft Security Blog’s Agent 365 GA announcement describes the risk plainly: without a unified control plane, IT, security, and business teams lack visibility into which agents exist, how they behave, who has access to them, and what potential security risks exist across the enterprise.

Agents can become, in Microsoft’s own framing, double agents, acting within systems with authorized access while behaving outside the boundaries of what was intended.

Agent 365 security addresses this through several layered controls:

  • Agent identity and authentication: Each agent has an Entra Agent ID with defined permission scopes. Access is governed by Conditional Access policies and enforced at runtime.
  • Least-privilege access for agents: Agents are granted only the permissions required for their defined function. Access reviews apply to agent permissions on the same cycle as human user reviews.
  • Shadow AI detection: The Agent 365 Shadow AI page in the Microsoft 365 Admin Center (Frontier preview) identifies unauthorized agents running in the environment before they create data security or compliance exposure.
  • Policy templates: Reusable policy templates group Entra, Purview, Defender, and SharePoint policies into standardized governance configurations that can be applied to agents at onboarding, ensuring consistent controls across the fleet without configuring each agent individually.
  • Lifecycle management: Rules-based automation handles ownerless agent reassignment, decommissioning of inactive agents, and auto-deployment of approved Microsoft-built agents, reducing manual overhead and governance gaps.

For organizations operating in HIPAA, PCI DSS, NIST, and SOC-governed environments, the compliance implications of unmonitored agents are direct. Agent interactions with regulated data must be auditable. Agent access to sensitive systems must be scoped and documented. Agent 365 provides the infrastructure to make that possible.

Ready to Take Control of Your Agent Environment?

Atmosera helps enterprises deploy and configure Agent 365 within their existing Microsoft security stack—governance, identity controls, and Defender integration included.

Request Your Free Azure Security Assessment

 

Agent 365 Governance and Dashboard: Visibility That Drives Accountability

The governance layer of Agent 365 is what turns visibility into control. Having a registry of agents is useful. Being able to act on what you see—enforce policies, revoke access, reassign ownership, flag compliance risks—is what makes governance operational rather than decorative.

The Agent 365 Dashboard

The Agent 365 dashboard provides a centralized view of every agent in the organization. For IT administrators, that means an inventory of agent ownership, deployment status, permissions, and policy alignment in one interface.

For security leaders, it means a consolidated view of AI-related risks, behavioral anomalies, and threat signals surfaced by Defender. For business stakeholders, it means performance metrics including the time saved by each agent on a weekly basis, enabling ROI measurement alongside risk management.

The dashboard consolidates telemetry from across the agent fleet. Activity logs, access patterns, tool usage events, and anomaly alerts surface in one place, with role-specific views that give each stakeholder the information relevant to their function without requiring them to navigate multiple separate platforms.

Lifecycle Governance and Ownership Accountability

One of the most persistent governance gaps in enterprise AI is agent orphaning—agents whose original creator has left the organization, moved to a different role, or simply stopped maintaining them. Orphaned agents retain whatever permissions they were granted at creation, potentially with access to systems they no longer serve a legitimate purpose in accessing.

Agent 365 addresses this through ownership tracking and automated lifecycle rules. Every agent in the registry has an assigned sponsor. When sponsors leave, ownership is automatically reassigned according to defined rules. Periodic attestation requirements prompt sponsors to confirm that agents under their ownership remain in active, legitimate use, surfacing agents that should be decommissioned before they become security liabilities.

Approval Workflows for New Agents

Organizations can configure Agent 365 to require IT approval before new agents are deployed into the environment. This approval workflow gives IT teams the ability to review an agent’s permissions, data access scope, and policy alignment before it begins operating, preventing unreviewed agents from accessing sensitive systems and ensuring that governance is applied at the point of entry, not retroactively.
 

Agent 365 vs Copilot Studio: Why the Answer Is Both

The comparison between Agent 365 and Copilot Studio is one of the most common points of confusion in enterprise AI planning. They appear, on the surface, to address similar territory. They do not.

Copilot Studio is where you build agents. Agent 365 is where you govern them. The two products operate at different points in the agent lifecycle and solve fundamentally different problems.

Copilot Studio is a low-code development environment. It enables developers and power users to design agents with specific behaviors, connect them to data sources and business systems, define conversational flows, and publish them to Teams, SharePoint, or other surfaces. It is a creation tool.

Agent 365 is a governance and security platform. It does not build or run agents. It observes, manages, and secures agents that already exist, regardless of whether they were built in Copilot Studio, Azure AI Foundry, AWS Bedrock, or any other platform. It is a control layer.

The key distinction is scope. Copilot Studio governs the agents you build with it. Agent 365 governs the agents your entire organization has built, bought, or inherited.

As Microsoft’s own Copilot Studio April 2026 update confirmed, the two platforms are designed to complement each other: “For Copilot Studio customers, this means the agents you create can be managed alongside agents from Microsoft 365 and partner ecosystems, with shared policies, security controls, and lifecycle oversight.”

The table below summarizes how the two platforms differ:

Dimension Copilot Studio Agent 365
Primary purpose Build and publish agents Govern, secure, and observe all agents
User Developers and power users IT admins, security teams, CISOs
Agent scope Agents you create in Copilot Studio All agents regardless of origin
Key capability Low-code agent development environment Unified control plane and registry
Security controls DLP and connector governance (limited) Full Entra, Purview, and Defender integration
Multi-cloud support Microsoft platforms Microsoft, AWS Bedrock, Google Cloud (preview)
Where it lives Power Platform / Copilot Studio portal Microsoft 365 Admin Center

 
For most enterprises running meaningful AI agent programs, the decision is not Agent 365 or Copilot Studio. It is both used together, with Copilot Studio as the development environment and Agent 365 as the governance layer that ensures what gets built stays within defined boundaries.

Agent 365 Licensing: What You Need to Know Before You Deploy

Agent 365 licensing is straightforward by design. It is licensed per user, not per agent. A single Agent 365 license covers all agents that a user interacts with, manages, or sponsors, regardless of how many agents that represents.

According to Microsoft’s official licensing FAQ, there are two primary ways to acquire Agent 365:

Option What’s Included
Agent 365 Standalone All Agent 365 capabilities; no M365 E7 required
Microsoft 365 E7 M365 E5 + Copilot + Entra Suite + Agent 365 bundled
Windows 365 for Agents Pay-as-you-go compute runtime for desktop/browser agents
M365 E3 / E5 Agent 365 NOT included; standalone add-on required

 

Key Licensing Details to Understand

  • Agent 365 is not included in Microsoft 365 E3 or E5. Organizations on these plans need the standalone add-on or an upgrade to E7 to access Agent 365 capabilities.
  • The per-user license covers all agents associated with that user. Microsoft recommends licensing all users of agents—those who interact with, manage, or sponsor agents in the environment.
  • Windows 365 for Agents is a separate, pay-as-you-go product for agents that require a full desktop or browser-based runtime environment.
  • Agent 365 requires at least one licensed user to enable the platform in a tenant. Microsoft also recommends Entra P1 or P2 and Purview Data Loss Prevention to make full use of the security and compliance capabilities.
  • The Microsoft 365 E7 bundle, at $99 per user per month, includes M365 E5, Copilot, Entra Suite, and Agent 365 together, priced below purchasing these components individually.

For organizations currently on M365 E5 that are actively deploying AI agents, the upgrade path to E7 is designed to be direct. E7 adds Copilot, Agent 365, and the Entra Suite to the security capabilities already in E5, bundled as a single enterprise AI and governance platform.
 

How Atmosera Helps You Get Agent 365 Right

Agent 365 gives your organization the infrastructure to govern AI agents at scale. What it does not give you automatically is the configuration, the integration work, and the operational discipline required to make that infrastructure effective.

The organizations that will get the most from Agent 365 are those that approach it not as a product to turn on but as a governance program to build, with a clear understanding of the agent landscape they already have, the policies they need to apply, and the security controls that need to be in place before adoption scales further.

Atmosera works with mid-market and large enterprises to:

  • Assess your current agent landscape and surface agents that exist in your environment without governance or ownership
  • Configure Agent 365 within your existing Microsoft 365, Entra, Purview, and Defender environment
  • Design approval workflows, lifecycle governance rules, and policy templates that match your organization’s compliance requirements
  • Integrate Agent 365 monitoring with your broader security operations, so agent risk signals are part of the same response workflow as identity and cloud alerts
  • Advise on licensing strategy, whether standalone Agent 365, E7, or a phased transition path makes the most sense for your current environment

With 27 years in business, Azure Expert MSP designation, eight Microsoft Gold Partnerships, and 24/7/52 US-based monitoring and support, Atmosera brings the operational depth required to move from Agent 365 deployment to genuine agent governance.

AI agents are not a future capability your organization is planning for. They are already operating in your environment. The question now is whether you have the visibility, the controls, and the governance framework to ensure they are working for you, not around you.

Ready to Bring Your Agent Environment Under Control?

Atmosera can help you assess your agent landscape, configure Agent 365, and build the governance program your organization needs to scale AI with confidence.

Contact Atmosera

 

Stay Informed

Sign up for the latest blogs, events, and insights.

We deliver solutions that accelerate the value of Azure.
Ready to experience the full power of Microsoft Azure?