en|de

Microsoft Agent 365: Maintaining Control Over AI Agents

AI agents have long been at work in many companies – whether as a Copilot extension, an automated workflow, or an independently developed assistant. With Microsoft Agent 365, Microsoft is introducing its first central platform for managing, securing, and monitoring these agents the way IT departments previously only knew from human user accounts.

What is Microsoft Agent 365?

Agent 365 is Microsoft’s answer to a problem that is becoming ever more pressing with the rise of Copilot and custom AI agents: every agent that accesses company data, sends emails, or triggers actions in business applications is essentially an independent actor on the network – but until now usually without an identity, access control, or audit trail. Agent 365 closes this gap by treating every agent like a digital employee: with its own identity, clearly defined rights, and complete traceability.

The core building blocks at a glance

  • Agent identity (Entra Agent ID): Every agent receives its own verifiable identity in Microsoft Entra – just like an employee’s user account.
  • Agent Registry: A central overview of which agents are active in the company, who created them, and what they are used for – important for avoiding “shadow agents”.
  • Security & governance: Direct integration with Microsoft Defender, Entra, and Purview, so that existing security and compliance policies automatically apply to agents as well.
  • Observability & monitoring: Traceable logging of which agent accessed which data at what time, or which action it triggered.
  • Lifecycle management: Governed processes for creation, approval, permission assignment and – just as important – the controlled decommissioning of agents that are no longer needed.

Why this is becoming urgent now

Many companies already use more AI agents than their IT department is aware of – whether through Copilot Studio, Power Automate, or departments setting up their own assistants. Without central governance, this quickly creates a shadow IT problem, only with agents instead of apps: unclear access rights, missing audit trails, and in the worst case agents that keep running even though nobody is responsible for them anymore. Agent 365 addresses exactly this risk before it becomes a compliance or security problem.

Agent 365 and licensing

Agent 365 is one of the four central building blocks of Microsoft 365 E7, the new “Frontier Suite”, alongside Microsoft 365 E5, Microsoft 365 Copilot, and the Microsoft Entra Suite. Companies that are already considering E7 licensing or planning individual agent add-ons should factor Agent 365 into their security architecture from the outset – not treat it as an optional extra.

What companies should do now

  • Get an overview of which AI agents are already in use in your company – including outside official IT procurement.
  • Check whether existing Entra, Defender, and Purview policies need to be sensibly extended to cover agents.
  • Define clear responsibilities for approving and decommissioning agents before their number becomes unmanageable.

We are happy to clarify whether and to what extent Agent 365 is worthwhile for your company, and how to govern your AI agents securely today, as part of a Microsoft Security Assessmentget in touch with us.

Leave a comment