Skip to content
Workflows Resources Case Studies Pricing About
Guides

AI Agent Governance: What Microsoft Agent 365 Changes

Microsoft Agent 365 adds a registry, agent identities, and audit controls for AI agents. Learn what it covers, what it costs, and the small-business version.

By Ahmad TawfikPublished 8 min read

When every employee had one login, IT security was comparatively simple. Now each business may soon have a dozen AI agents booking appointments, chasing invoices, answering chats, and touching customer data around the clock. Microsoft's answer to that sprawl is Agent 365, a control plane for observing, governing, and securing every agent in an organization. It went generally available on May 1, 2026, and even if you never buy it, the discipline behind it is worth understanding, because the same problems show up in a ten-person company.

Key takeaways

  • Microsoft Agent 365 is a management layer for AI agents: a registry, an identity for each agent, lifecycle rules, access policies, threat protection, and audit logging.
  • Every agent gets an Agent ID in Microsoft Entra, treated much like a user or app account, so access can be granted, limited, and revoked per agent.
  • Pricing is $15 per user per month standalone, or included in the Microsoft 365 E7 plan at $99 per user per month.
  • Defender covers agent-specific attacks such as prompt manipulation, model tampering, and multi-agent attack chains; Purview adds sensitivity labels, data-loss prevention, and audit support.
  • Small businesses can copy the core habits without the product: one identity per agent, least-privilege access, approval gates, logging, and a named owner.

What Agent 365 actually is

Think of it as the difference between letting everyone use one shared key to the office and giving every person their own badge. Before Agent 365, AI agents in most companies ran on borrowed credentials: an employee's login, a shared API key, an automation nobody remembered setting up. When something went wrong, nobody could say which agent did what, with whose permission, or how to switch it off without breaking three other things.

Agent 365 puts a management layer over that mess. Its pieces, in plain language:

  • A unified agent registry. Every agent in the organization is listed in one place, with an owner, a purpose, and a status. No more mystery bots.
  • Agent ID. Each agent gets its own identity in Microsoft Entra (Microsoft's login and directory system), similar to how a user or an application has an account. That identity is what access rules attach to.
  • Lifecycle management. Inactive agents can expire automatically, agents with no owner get flagged, and risky agents can be blocked outright.
  • Access control. Conditional access and risk-based policies apply to agents the way they apply to people: where they can connect from, what they can reach, and what triggers extra scrutiny.
  • Threat protection. Microsoft Defender watches for agent-specific attacks, including prompt manipulation, model tampering, and attack chains that hop between agents.
  • Data security. Microsoft Purview brings sensitivity labels, data-loss prevention, insider-risk signals, and audit and eDiscovery support to agent activity.
  • Observability. Activity streams over OpenTelemetry, an industry-standard logging format, so agent behavior can flow into the same monitoring tools a company already uses.

One detail matters for buyers who do not live entirely in Microsoft's world: agents built on other platforms can be brought under the same controls through an SDK. Governance does not stop at the Microsoft boundary.

How the controls map to problems you already have

The enterprise vocabulary can sound abstract, so here is what each control prevents in a small-business setting:

Agent 365 controlThe problem it solvesSmall-business equivalent
Agent registryMystery automations nobody ownsA one-page list of every agent, its job, and its owner
Agent ID in EntraAgents sharing your personal loginA dedicated login or API key per agent
Lifecycle rulesForgotten agents running foreverA quarterly check: still needed, still owned, still correct
Conditional accessAn agent acting from anywhere, anytimeLimits on what systems each agent can reach
Defender threat protectionHijacked or tampered agentsApproval gates plus monitoring (see below)
Purview data securityCustomer data leaking through agentsRules on which data each agent may see or send
Audit and observabilityNo record of what the agent didA log of actions, approvals, and data touched

If that table looks familiar, it should. Our guide to AI agent audit trails covers the logging habit in detail, and agent identity management explains the one-login-per-agent rule step by step.

What it costs and who it is for

Agent 365 costs $15 per user per month, or comes included with Microsoft 365 E7 at $99 per user per month. That pricing tells you who Microsoft built it for: organizations already deep in the Microsoft 365 ecosystem, with enough agents and enough regulatory exposure that centralized governance pays for itself.

A five-person plumbing company or a solo law practice does not need an enterprise control plane. What it needs is the discipline the product enforces, applied with lighter tools. The cost of skipping that discipline is concrete: an agent running on the owner's email login keeps working after the employee who set it up leaves, a booking agent with full inbox access can expose every client conversation, and when a customer asks what your agent did with their data, "we don't keep a record" is a bad answer.

Larger service businesses, especially those handling health, legal, or financial data, sit in the middle. If you already pay for Microsoft 365 and run several agents across sales, scheduling, and support, Agent 365 is worth evaluating with your IT provider. If you run one or two agents through a vendor like Praktivo, the vendor should be able to show you the same fundamentals: isolated credentials, scoped access, approval workflows, and logs. Our internal assistant service is built around those defaults, and the internal assistant workflow shows how scoped back-office agents stay inside their lane.

Where OpenAI Dots fit into this picture

One reason Agent 365 matters beyond Microsoft shops is the OpenAI connection. OpenAI's always-on agents, called Dots and announced at Dev Day on September 29, 2026, each run on their own cloud computer, connect to thousands of business apps, and can take actions across Slack, Teams, voice calls, and more, with approvals and an Activity View for oversight. OpenAI is now working with Microsoft to bring its specialist business Dots, built for procurement, invoice processing, customer support, and commercial contracts, with their own identities and access to selected company systems, into Agent 365 security controls.

That partnership is a signal about where the market is going: agents from different vendors, governed under one set of rules. For a business owner, the practical lesson is to ask every agent vendor the same governance questions, regardless of whose logo is on the agent. Who is the agent's identity? What can it touch? Who approves sensitive actions? Where is the log? A vendor that answers crisply is a vendor that has done this work; a vendor that waves it away has not.

The small-business version of Agent 365

You can stand up a workable governance routine in an afternoon. Here is the short version:

  1. List every agent. Name, job, owner, systems it touches. One page. Update it when something changes.
  2. Give each agent its own credentials. Never run an agent on your personal login. If the agent only needs the calendar, it gets the calendar, not the inbox.
  3. Set approval tiers. Routine lookups can run automatically; anything involving money, customer data leaving the building, or messages sent in your name needs a human yes.
  4. Keep a log. Record what each agent did, what it was asked, what it touched, and who approved the sensitive steps. Keep routine logs at least 90 days; keep anything tied to money or regulated data longer.
  5. Assign an owner and a review date. Every agent has one human responsible for it. Every quarter, confirm the agent is still needed, the access is still right, and the owner still works there.

None of this requires enterprise software. It requires deciding that agents are staff, not toys, and treating them with the same seriousness you would give a new hire's keys, passwords, and permissions.

FAQ

What is Microsoft Agent 365?

It is a control plane for AI agents inside organizations that went generally available on May 1, 2026. It provides a unified agent registry, an Agent ID identity in Microsoft Entra for every agent, lifecycle management, conditional access policies, Defender threat protection, Purview data security, and OpenTelemetry-based observability, including for agents built on other platforms via an SDK.

How much does Microsoft Agent 365 cost?

Agent 365 costs $15 per user per month as a standalone add-on, and it is included in the Microsoft 365 E7 plan at $99 per user per month. Small businesses that do not run Microsoft 365 can replicate the core discipline, one identity per agent, scoped access, approvals, and logging, with the tools they already own at little extra cost.

Does Agent 365 only govern Microsoft-built agents?

No. Microsoft designed it to observe and secure agents built on other platforms as well, through an SDK that brings outside agents under the same registry and policy controls. OpenAI, for example, is working with Microsoft to bring its specialist business Dots for procurement, invoicing, support, and contracts into Agent 365 security controls.

What should a small business copy from Agent 365?

Four habits cover most of the value: give every agent its own login instead of sharing yours, grant the smallest access that gets the job done, require approval before money or customer data moves, and keep a log of what each agent did. Assign one person as the owner of every agent and review access quarterly.

Next step

List every AI agent and automation touching your business today, with its owner and what systems it can reach. If that list has gaps, or if any agent runs on your personal login, that is your first fix. Our free six-step AI automation plan maps your current setup and prioritizes the gaps: start your AI automation plan. To review your agent setup with someone, book a call.

Frequently asked questions

What is Microsoft Agent 365?
It is a control plane for AI agents inside organizations that went generally available on May 1, 2026. It provides a unified agent registry, an Agent ID identity in Microsoft Entra for every agent, lifecycle management, conditional access policies, Defender threat protection, Purview data security, and OpenTelemetry-based observability, including for agents built on other platforms via an SDK.
How much does Microsoft Agent 365 cost?
Agent 365 costs $15 per user per month as a standalone add-on, and it is included in the Microsoft 365 E7 plan at $99 per user per month. Small businesses that do not run Microsoft 365 can replicate the core discipline, one identity per agent, scoped access, approvals, and logging, with the tools they already own at little extra cost.
Does Agent 365 only govern Microsoft-built agents?
No. Microsoft designed it to observe and secure agents built on other platforms as well, through an SDK that brings outside agents under the same registry and policy controls. OpenAI, for example, is working with Microsoft to bring its specialist business Dots for procurement, invoicing, support, and contracts into Agent 365 security controls.
What should a small business copy from Agent 365?
Four habits cover most of the value: give every agent its own login instead of sharing yours, grant the smallest access that gets the job done, require approval before money or customer data moves, and keep a log of what each agent did. Assign one person as the owner of every agent and review access quarterly.
Keep reading

Related articles

Get Your AI Automation Plan