Lifelongnerd
Field Notes from the Frontier
← Hub
Field Tool · Agent Governance

Agent 365
Governance Planner

Agents are already in your tenant. This planner scores your readiness across six governance pillars, builds your working checklist, maps every control to the portal it lives in, and helps you pick the right build path — before sprawl picks it for you.

Updated Oct 10, 2026 · Agent 365 GA since May 1, 2026 · sources linked throughout

The control plane for agents

Agent 365 extends the tools you already run — Entra, Defender, Purview, Intune, and the Microsoft 365 admin center — to AI agents. Microsoft frames it around three verbs: observe, govern, secure. It reached general availability on May 1, 2026, standalone at $15/user/month or inside Microsoft 365 E7.

Observe
registry · agent map · usage & health reports
+
Govern
lifecycle · access policies · compliance
+
Secure
Defender · Entra · Purview risk signals

Five things it gives you

01 · Registry

One inventory

Every agent — Microsoft, partner, org-built, and imported third-party — in a single registry in the Microsoft 365 admin center, with a Risks column aggregating high-severity signals from Entra, Defender, and Purview.

Find it at Agents > All Agents > Registry. Microsoft sorts every agent into four types: Microsoft agents, external partner-built agents, agents published by your org, and agents shared by their creator.

learn.microsoft.com →
02 · Identity

Entra Agent ID

Each agent gets its own first-class identity — built on service-principal infrastructure with an agent-specific subtype — so Conditional Access, auditing, and lifecycle management work the way they do for humans.

learn.microsoft.com →
03 · Visualization

Agent map & telemetry

Dashboards, usage metrics, and an agent map that visualizes how agents connect to users, data, and each other — role-tuned so compliance, security, and IT each see the signals they own.

microsoft.com →
04 · Interoperability

Beyond Microsoft

Registry sync imports AWS Bedrock and Google Gemini Enterprise agents (preview), and Defender + Intune discover local agents on Windows endpoints — starting with OpenClaw, expanding to GitHub Copilot CLI and Claude Code.

microsoft.com/security →
05 · Security

Defense in depth

Defender delivers runtime protection and end-to-end activity tracing; Purview enforces data protection, DLP, and audit; Entra network controls extend to Copilot Studio agents and endpoint agents for traffic inspection.

microsoft.com/security →

Blueprint → Instance

The two objects you'll actually manage. A blueprint is the template — credentials, auth settings, inheritable permissions. An instance is the tenant-specific deployment with its own Entra Agent ID.

Template · owned by builders

Agent Blueprint

  • Defines capabilities and behavior rules
  • Holds credentials and auth settings
  • Permissions instances can inherit
  • Provisions or deprovisions instances
Deployment · owned by IT

Agent Instance

  • Its own Entra Agent ID
  • Tenant-specific configuration
  • Scoped, least-privilege access
  • Governed in the Agent Registry

Where agents come from

Microsoft agents

Pre-built agents like Researcher and Analyst, maintained by Microsoft. IT can pin, block, or restrict them via the registry — and install first-party agents in bulk with agent management rules.

Partner agents

Ecosystem agents from ISVs — Adobe, SAP, ServiceNow, Workday, Zendesk, n8n, and more — manageable through Agent 365 and deployable from the admin center.

Org-published agents

Built by your makers and developers in Copilot Studio or Foundry, then reviewed and published through your approval workflow. Your knowledge bots and process agents.

User-shared agents

Personal productivity agents users create and optionally share. Lowest ceremony, highest sprawl risk — exactly what naming conventions and lifecycle rules exist for.

Local & shadow agents

CLI and desktop agents running on endpoints, plus unregistered SaaS AI. The Shadow AI page, Entra discovery, and Intune policies exist to find and fence these.

Imported multicloud agents

AWS Bedrock and Google Gemini Enterprise agents synced into the registry (public preview), so your inventory isn't three consoles and a spreadsheet.

Readiness assessment

24 questions across six pillars. Answer honestly — "in progress" is a legitimate answer, and the plan this generates is only as good as the inputs. Your answers stay in this browser (localStorage) and can be shared as a link.

tip: press 1 2 3 to answer ·

Governance checklist

The working list. Click the square to cycle each item: not started → done → partial. Filter by role to see just your lane. Progress saves in this browser; export CSV for your tracker of choice.

Click to cycle:not starteddonepartial
0% complete

Naming convention builder

Sprawl starts with names. A registry full of "Test agent (2)" is unsearchable, unownable, and unretirable. Build your pattern here, then enforce it in the publish workflow — the generated metadata block goes straight into your governance doc.

Registry name
Metadata block · required at publish

    

Why this shape: the registry sorts alphabetically, so AGT- groups agents together, org+dept makes filters trivial, source code tells security the trust tier at a glance, and ENV keeps test agents out of production searches.

The first 90 days

Observe, then govern, then secure — in that order. Governing an inventory you haven't seen yet is how policies get written for a fleet that doesn't exist.

Days 0–30

Observe

  • Baseline the Agent Registry against what teams say they run — the delta is your shadow problem
  • Turn on shadow-AI discovery (Entra) and review the Shadow AI page for local endpoint agents
  • Walk the agent map; flag over-connected agents and anything with no obvious owner
  • Kick off the oversharing assessment — agents will surface whatever permissions allow
  • If multicloud: enable Bedrock / Gemini registry sync (preview) so it's one list
Exit criteria: a complete inventory, every agent's owner known or flagged, oversharing scope sized.
Days 31–60

Govern

  • Enforce the naming convention + metadata block (above) in a documented publish workflow
  • Issue Entra Agent IDs for all sanctioned agents; kill shared registrations and standing maker credentials
  • Apply Entra security policy templates, then tighten toward least privilege per agent
  • Define the ownerless-agent default — reassign or retire — and automate it
  • Use agent management rules for bulk actions instead of one-at-a-time clicking
Exit criteria: nothing publishes without a name, an owner, and a review date.
Days 61–90

Secure & scale

  • Extend sensitivity labels and Purview DLP to agent interactions; turn on agent audit review
  • Agree the IT / SOC split; exercise the rogue-agent playbook (block → revoke → investigate)
  • Adopt the Defender advanced-hunting templates for agents
  • Extend Entra network controls to Copilot Studio and endpoint agent traffic
  • Start the cadence: usage reviews with owners, retire what nobody uses
Exit criteria: an incident involving an agent has a rehearsed path from alert to block in minutes, not meetings.

Portal map

The question every admin actually asks: where do I click? Agent 365 isn't one portal — it's capabilities threaded through five. Here's who goes where.

admin.microsoft.com

M365 Admin Center

The Agent 365 overview dashboard and Agent Registry. Publish, pin, block, remove, reassign. Risks column, Shadow AI page, agent management rules for bulk actions, ownerless-agent management.

entra.microsoft.com

Microsoft Entra

Agent IDs, ownership, least-privilege access, Conditional Access for agents, network controls and traffic inspection, shadow-AI discovery via Entra Internet Access.

security.microsoft.com

Microsoft Defender

Runtime threat detection, incident graphs including agent activity, advanced-hunting templates (e.g., agents running MCP tools on a maker's standing credentials), local-agent discovery.

purview.microsoft.com

Microsoft Purview

Sensitivity labels, DLP for agent interactions, audit of agent activity, insider-risk and compliance signals that surface in the registry's Security tab.

intune.microsoft.com

Microsoft Intune

Endpoint policies for local agents: detect managed devices running unmanaged agents and block common launch paths. Windows 365 for Agents Cloud PCs for policy-controlled agent workloads.

Roles & responsibilities

RoleOwns
AI AdministratorAgent Registry day-to-day: publish, block, remove, approval workflows, management rules
AI ReaderView-only registry access — least privilege for reporting and audit
Global AdminTenant-wide control; delegates operations to the AI Administrator
Security AdminDefender monitoring, Conditional Access for agents, incident response
Compliance AdminPurview policies, sensitivity labels, DLP, audit review
Agent OwnerOne agent's lifecycle: reviews, updates, retirement — every agent needs one
Business SponsorBusiness case, success metrics, budget for major agent deployments

Licensing quick-ref

Agent 365 standalone

$15/user/month — the control plane on its own. Per-seat, on the M365 invoice. Microsoft recommends pairing with Entra ID P1/P2 or Entra Suite plus Purview DLP to use it fully.

Microsoft 365 E7

The "Frontier Suite" — bundles E5, Microsoft Copilot, Entra Suite, and Agent 365 in one SKU. GA alongside Agent 365 on May 1, 2026.

techcommunity →

What Copilot doesn't cover

A Microsoft Copilot license lets people use and build agents — it does not include Agent 365 governance. Building runs on Copilot Studio / Foundry (consumption, Azure invoice); governing is Agent 365 (per-seat).

Key terms

Entra Agent ID

A dedicated identity type for agents — service-principal infrastructure with an agent-specific subtype, so CA, audit, and lifecycle work like they do for users.

Agent Blueprint

The parent template object: credentials, auth settings, inheritable permissions. Its one job in the tenant is provisioning or deprovisioning instances.

Agent Instance

A tenant-specific deployment of a blueprint, with its own Agent ID and configuration, managed by IT in the registry.

Agent Registry

The central inventory in the M365 admin center — adoption, activity, health, and aggregated risk per agent, with block/restrict actions inline.

Agent Store

The marketplace for discovering and installing Microsoft and partner agents; IT controls what's allowed in the tenant.

Agent Map

Visualization of how agents connect to users, resources, and other agents — the fastest way to spot an over-connected agent.

Shadow agents

AI tools operating without IT visibility — SaaS agents, local CLI agents, personal accounts. The gap discovery features exist to close.

Windows 365 for Agents

Cloud PCs purpose-built to run agent workloads inside policy-controlled environments instead of on someone's laptop.

Build path decider

"We need an agent" is a sentence, not a plan. Answer a few questions and get the right path — plus the governance steps that path implies.

Field FAQ

The questions that come up in real customer conversations, with sources.

Is Agent 365 generally available?

Yes — GA on May 1, 2026, alongside Microsoft 365 E7. The Frontier program continues as the early-access path for preview features without production SLAs.

Microsoft Security Blog — GA announcement →

What does it cost, and what license do I need?

$15/user/month standalone, or included in Microsoft 365 E7 (which bundles E5, Microsoft Copilot, Entra Suite, and Agent 365). A Microsoft Copilot license alone does not include Agent 365 governance. Pairing with Entra ID P1/P2 or Entra Suite plus Purview DLP is recommended to light up the full capability set.

Microsoft's own overview says Agent 365 works best with Microsoft E5 as a prerequisite, and that at least one user must hold a qualifying Agent 365 licence before it can be enabled.

Agent 365 product page → · Agent 365 overview on Learn →

Does Agent 365 govern agents outside Microsoft?

Increasingly, yes, and the list has grown fast. The Connected platforms page in the Microsoft 365 admin center now syncs agents into the registry from Amazon Bedrock, Google Vertex AI, Anthropic Claude Managed Agents, Salesforce Agentforce, Databricks Genie, Oracle Generative AI Agents and Snowflake Cortex. Two caveats worth saying out loud: synchronisation is manual — you press Sync agents, there's no live feed — and activity telemetry (the Collect agent observability data switch) is only live for Bedrock, Vertex AI and Claude today, and is a Frontier preview. Ecosystem partners — Adobe, SAP, ServiceNow, Workday, Zendesk, Manus, Genspark, n8n — also ship agents manageable through Agent 365.

Connected platforms on Learn → · GA announcement →

What about agents running locally on laptops?

There is a Shadow AI page in the Microsoft 365 admin center for exactly this — but set expectations carefully, because it is still a Frontier public preview, not GA. Detection today covers OpenClaw, ChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw/ZeroClaw, OpenCode and Claude Desktop, and shows you the devices and users each one is running on. Blocking is available for OpenClaw only: Agent 365 writes an Intune policy named A365 - Block OpenClaw that stops the common launch paths, and it only reaches managed Windows devices enrolled in Intune. Prerequisites are real — Frontier opt-in, Defender for Endpoint on the devices, Microsoft 365 E5 to see the list, and Global Secure Access if you want the traffic and last-used detail populated.

Shadow AI docs → · GA announcement →

What's the difference between Agent 365 and Copilot Studio?

Copilot Studio (and Azure AI Foundry) is where agents get built and run — developer-side, consumption-billed on Azure. Agent 365 is where agents get governed — identity, access, compliance, lifecycle — per-seat on the M365 invoice. Workshop vs. HR department.

Agent 365 overview on Learn →

How do I find risky agents fast?

Start at the Agents at risk tile on the All agents page — it gives you the count and a prefiltered list in one click, and the same top-three view sits on the admin center Overview page. Per agent, the Risks column shows an aggregated signal count across all severities, not just high; selecting it opens a Risk details pane with the signals grouped into high, medium and low sections, an occurrence count each, and deep links out to whichever of Purview, Entra and Defender raised them. Two things to know before you demo it: the counts can lag the security portals by up to an hour, and viewing risk signals at all requires an E7 or Agent 365 licence. SOC teams still get the full incident graph in Defender.

Agent Registry docs →

Can I filter the registry by how an agent was built?

Yes. Beyond status, publisher type, channel, and platform, the registry has a data-source filter with two options: agents carrying embedded knowledge (files the maker uploaded) and agents built on fine-tuned models through Microsoft Copilot Tuning. Both are worth a look in a data-risk review, because uploaded files and tuned models carry organisational data inside the agent itself.

Agent Registry docs →

What happens to an agent when its owner leaves?

Without a policy: it keeps running, unowned. The admin center gives you an Agents without owners card with a live count and a one-click filter — the count updates itself when you hard-delete a user — but the only actions it offers on those agents are block and delete. There is no reassign button. So the handover plan has to live in your governance policy, decided before it happens: who inherits, or how long the grace period runs before someone blocks it.

Agent Registry docs →

Can I manage the registry with a script instead of the portal?

Partly, and it's in preview. Microsoft Graph endpoints now expose the agent inventory: a GET packages call returns every agent in the tenant, and a GET package details call returns the metadata for one. That covers reporting, compliance exports and onboarding automation. It runs under the AI Administrator role. Write operations are not there yet — bulk changes still go through the admin center.

Agent Registry docs →

Can I use this planner before buying anything?

That's the point. The assessment and checklist are about the framework — ownership, naming, approval flow, data hygiene — which you want in place before agents scale, not after. Nothing here requires a license.