Microsoft Agent 365 is a centralized control plane for discovering, governing, monitoring and securing AI agents across an organization. Microsoft introduced it at Ignite in November 2025 and made it generally available to commercial customers on May 1, 2026. It is designed to give IT teams an inventory of agents, accountable owners, permission visibility and lifecycle controls—not to replace tools that build agents.
Why Microsoft is concerned about “agent sprawl”
Microsoft uses “agent sprawl” to describe an emerging management problem: employees, business units, developers and vendors can create or acquire agents faster than IT can record and govern them. An organization may not know how many agents exist, who is responsible for each one, what data they can access, which tools or APIs they can call, or whether they are still needed.
The risk is not simply the number of agents. It is the combination of autonomy, data access, tool access and unclear accountability. An agent may retain permissions after its owner changes jobs, continue operating after a business process ends, or use broader rights than its task requires. Traditional application inventories are generally organized around software, users, devices and service accounts; Agent 365 treats the agent itself as an enterprise object that needs identity and lifecycle management.
This is Microsoft’s strategic framing rather than a quantified claim that every organization already has a crisis. The practical issue is familiar to IT leaders: unmanaged automation can create security, compliance and cost exposure.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problems#1 Best Overall
What Microsoft announced, and what is available now
- November 2025: Microsoft introduced Agent 365 at Microsoft Ignite as a control plane for AI agents.
- March 9, 2026: Microsoft announced the May 1 general-availability date and described a single place to observe, govern, manage and secure agents.
- May 1, 2026: General availability began for commercial customers.
- June 2026: Microsoft’s overview and service description documented the available management, governance, observability and security capabilities.
As of August 18, 2026, it should therefore be described as generally available for commercial customers, not merely announced or in preview. See Microsoft’s overview and general-availability announcement.
What Agent 365 actually does
Builds an agent inventory
The Agent Registry records information such as an agent’s name, description, publisher, platform, owner, deployment status, permissions, data and tool access, security and compliance information, and usage activity. Agents built with Microsoft technologies can be listed alongside agents from ecosystem partners and external platforms when those integrations support synchronization.
External synchronization does not mean identical control. The metadata, telemetry and enforcement available for a third-party agent can be narrower than for an agent deeply integrated with Microsoft services. Microsoft documents the registry and feature matrix in its service description.
Rank #2
Controls the lifecycle
Inventory is useful only when administrators can act on it. Agent 365 supports governance actions including:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Publishing, deploying, approving, blocking and deleting agents.
- Assigning agents to users or groups.
- Reassigning ownership and pinning approved agents.
- Automating actions with condition-based lifecycle rules.
A controlled lifecycle should move an agent from discovery and review to approval, deployment, monitoring, reassignment, suspension and retirement. The exact enforcement available depends on the agent’s platform and integration.
Assigns identity and accountability
Agent 365 works with Microsoft identity infrastructure, including Microsoft Entra Agent ID. Administrators can associate an agent with an owner, sponsor or manager, control who may create or administer agents, and use sponsor-lifecycle workflows so responsibility does not disappear when an employee leaves or changes roles.
Shows activity and telemetry
Premium capabilities provide observability and monitoring intended to show how agents are being used and help identify unusual or unacceptable activity. Coverage is not guaranteed to be complete: event detail and behavioral visibility vary by agent type, platform and integration. Telemetry can show activity and tool calls, but it does not make every model decision explainable.
Connects to security and compliance controls
Microsoft positions Agent 365 as an orchestration layer across existing services:
- Entra: agent identity and access management.
- Defender: threat detection and runtime protection.
- Purview: data security, compliance and data-loss controls.
- Intune: device-compliance conditional access and policy-controlled runtime environments.
It is not a standalone console that replaces Entra, Defender, Purview or Intune. Administrators may still work in the Microsoft 365 admin center and those related portals.
Governs tools and permissions
Recent updates describe centralized management of tools an agent can use, including the ability to view, allow or block tools such as Microsoft MCP servers. Access packages can define agent permissions, while sponsor workflows preserve accountability.
Reviews should cover Microsoft Graph permissions, files and mailboxes, sites and databases, external APIs, runtime identity, whether the agent can write or delete data, and whether consequential actions require human approval. Listing an overpowered process in a registry does not make it safe; least-privilege design remains essential.
How the intended governance workflow works
- An employee or developer creates an internal agent, or a business unit adopts one from a vendor.
- The agent and available metadata appear in the Agent Registry, or an external integration synchronizes them.
- IT records an owner or sponsor and reviews data access, tools, permissions and deployment status.
- Administrators approve and deploy the agent to selected users or groups, or block it if the risk is unacceptable.
- Policies, identity controls and conditional-access requirements govern use.
- Telemetry and usage insights help security teams investigate activity and identify dormant or unusual agents.
- If the owner leaves, the use case changes or the process ends, IT reassigns, suspends or retires the agent.
This is the intended operating model, not a promise of universal discovery or identical controls. Shadow deployments, unsynchronized SaaS agents, embedded business-application agents and shared service accounts can remain blind spots.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
Which agents are covered?
Agent 365 is intended for Microsoft-built agents, organization-built agents created with Microsoft platforms, partner agents and external-platform agents that can be synchronized into the registry. Basic inventory and governance features apply across eligible Microsoft 365 enterprise, business, education and first-line-worker plans, while advanced policy, observability, compliance and runtime capabilities depend on the entitlement.
“Covered” therefore does not mean “controlled identically.” A third-party agent may be visible without exposing the same policy enforcement or telemetry as a Microsoft-integrated agent. Organizations with substantial non-Microsoft estates should validate integration depth before assuming complete coverage.
Licensing and current Microsoft-listed prices
| Option | Microsoft-listed signal | What it means |
|---|---|---|
| Standalone Agent 365 | $15 per user per month | An add-on for eligible Microsoft 365 customers; terms, geography and purchasing channel apply. |
| Microsoft 365 E7 | $99 per user per month | A broader bundle including Agent 365, Microsoft 365 Copilot, Microsoft Entra Suite and Microsoft 365 E5 security capabilities. |
| Foundational capabilities | Included for Microsoft Cloud subscription customers, subject to Microsoft’s terms | Basic agent identity, inventory visibility, usage insights and core administrative governance actions. |
Microsoft licenses Agent 365 per user, not per agent. A licensed user can be associated with multiple agents, and agents do not require individual licenses. Microsoft recommends licensing users who interact with, manage, own or sponsor agents; pooling users to reduce the requirement is not permitted. That can make the total cost materially higher than multiplying the number of agents by $15.
Premium capabilities include advanced usage analytics, governance policies, security-posture management, threat detection and data-security controls. Compare the incremental license with entitlements the organization already owns rather than assuming E7 is a cheaper alternative: E7’s value depends on whether the customer also needs its Copilot, identity and security bundle. See Microsoft’s licensing FAQ.
Who should evaluate Agent 365?
- Large Microsoft 365 estates deploying many Copilot or custom agents.
- Regulated organizations that need ownership, permission review and auditability.
- Security teams concerned about shadow AI and unattended action-taking systems.
- Organizations already using Entra, Defender, Purview, Intune, Copilot Studio or Microsoft Graph.
- Enterprises that need to assign identities and retirement responsibilities as agents proliferate.
It may be less compelling for a small organization with a few manually reviewed agents, a company with little Microsoft 365 adoption, or an enterprise whose agents primarily run on other clouds and cannot provide equivalent registry data and controls. Those are evaluation inferences, not universal product limitations.
Questions to answer before buying
- Can the organization discover every known agent, including external and embedded deployments?
- Are owners and sponsors mandatory, and are review intervals enforced?
- Can risky agents, tools or permissions be blocked automatically?
- Can permissions be revoked centrally across third-party platforms?
- Which users need premium licenses: creators, owners, sponsors, administrators, analysts and ordinary users?
- Can the organization monitor agents that send messages, modify records, approve transactions, change permissions, invoke APIs or run unattended?
- Which capabilities are already included in existing Microsoft 365, Entra, Defender, Purview and Intune agreements?
Bottom line for IT and procurement
Agent 365 is Microsoft’s attempt to make AI agents manageable as enterprise identities and applications. Its strongest case is an organization moving from a few pilots to a fleet of agents that need inventory, accountable ownership, least-privilege permissions, monitoring and retirement rules. Its value will depend less on the existence of a registry than on discovery coverage, enforceable controls, third-party integrations and the number of users that must be licensed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




