Microsoft Agent 365: Control Plane for AI Agents

Bring AI agents under control with one governance layer: Effective May 1, 2026, Microsoft Agent 365 becomes generally available as a control plane for AI agents.

 

Summary

  • Microsoft Agent 365 becomes available on May 1, 2026.
  • The price is $15 per user per month as add-on*, and it is part of Microsoft 365 E7.
  • Observe, govern, manage, and secure AI agents across the organization.
  • The service covers agents built with Microsoft AI platforms and agents from ecosystem partners.

*Prices in this article are for educational purposes only and are non-binding.

 

What is Microsoft Agent 365?

Available from May 1, 2025, Microsoft Agent 365 is a control plane for managing Artificial Intelligence (AI) agents at scale. AI agents are software programs that perform tasks autonomously using AI. As these agents become more common, organizations need tools to manage them securely and efficiently.

Agent 365 allows companies to treat AI agents like employees in their IT systems. It integrates with Microsoft 365 tools and services, thereby enabling centralized oversight, identity management, access control, and security for all agents. The solution covers all kinds of AI agents: built in-house, open-source, or from third parties.

Just as Microsoft 365 is securing your users and data, Agent 365 will be securing and managing your AI agents.

Within the Microsoft ecosystem, Agent 365 connects Microsoft 365 administration with Microsoft Entra, Microsoft Defender, and Microsoft Purview capabilities.

 

Licensing

From a licensing perspective, Microsoft has announced standalone pricing of $15 per user per month*, while also positioning Agent 365 as part of the broader Microsoft 365 E7 offering.

 

Key Features

  • Registry
    A centralized inventory of all AI agents in the organization. It includes agents with Microsoft Entra IDs, those registered in the Agent Store, and even “shadow agents.” IT administrators can quarantine unauthorized agents to prevent access to systems or data.

  • Access Control
    Each agent receives a unique agent ID, enabling precise control over access to resources. Policy templates and adaptive access controls ensure agents operate with the least privilege necessary, reducing risk.

  • Visualization
    A unified dashboard provides visibility into agent activity, connections, and performance. Role-based reporting delivers tailored insights for IT, security, and business leaders. Built-in metrics help assess agent effectiveness and return on investment.

  • Interoperability
    Agents can access the same tools and data as employees, including Microsoft 365 apps and business systems like SharePoint and Dynamics 365. Agent 365 supports agents from Microsoft, Adobe, ServiceNow, Workday, and others, ensuring flexibility across platforms.

  • Security
    Agent 365 integrates with Microsoft DefenderMicrosoft Entra, and Microsoft Purview to protect agents and data. It detects threats, blocks compromised agents and enforces compliance policies. All agent interactions are logged for auditing and investigation. As of July 1, 2026, Microsoft Defender agent protection capabilities – previously free during public preview – require Microsoft Agent 365 licensing, available through Microsoft 365 E7 or as a standalone license.

 

 

Why Agent 365 is now more relevant than ever before

AI agents are the future of the modern workplace. They do tasks automatically, hence helping human employees. This is the beginning of a new era of licensing, in which AI agents will replace some of the licensed “employees”. Microsoft is providing new tools and licenses for this shift in modern organizations. AI agents need to be managed too, from a licensing perspective, but more importantly, from the security side of things.

Agent 365 offers better control over agent growth, more clarity on agent activity, less manual coordination across tools, and a more structured path to secure adoption. That matters most for organizations that want AI scale without increasing unmanaged risk.

 

FAQ

Does Agent 365 automatically expire or clean up unused agents?

Agent 365 supports manual lifecycle actions such as assigning sponsors, suspending agents, and retiring agents. Policy-based lifecycle automation such as expiration warnings or inactivity-based cleanup is planned and will roll out incrementally.

Can external users email or contact an agent?

Yes. External users can email or contact an agent, but only if your organization’s policies allow it. By default agents behave as internal identities, and external access is controlled or restricted through admin settings.

What happens if an agent is deleted or deactivated?

The associated license is released and becomes available for another agent instance.

Can customers prevent “shadow agents” or unapproved agents?

Yes. Customers will be able to require that only registry‑approved agents can run, block or restrict unregistered agents, and use policies to enforce approval before deployment, with preview already providing visibility and enforcement expanding over time.

Can Agent 365 govern agents built outside Microsoft (e.g. ChatGPT Enterprise, AWS, GCP)?

Yes, if the agent is onboarded using the Agent 365 SDK. SDK integration enables inclusion in the Agent 365 Registry, observability telemetry, and policy enforcement via Entra, Defender, and Purview. Agents not integrated via the SDK are not governed at the agent identity level.

External or SAAS agents that are not onboarded via the SDK cannot be governed at the agent identity level. However, they can still be discovered as shadow agents through Microsoft security signals such as Defender and Entra. Discovery allows organizations to detect and restrict activity, but full governance requires explicit onboarding and registration in Agent 365.

When a third-party agent is onboarded through the Agent 365 SDK and assigned an Entra Agent ID, it appears in the Agent 365 dashboard. From there, admins can see:

  • Active users and departments
  • Frequency and usage trends
  • Lifecycle status
  • Agent identity and ownership details

This allows security and IT teams to distinguish approved agents from unsanctioned shadow agents and take action directly in the admin center.

Can employees still use agents without registering them in Agent 365?

Today: Shadow agents can still run. Agent 365 discovers them, surfaces their activity, and flags unmanaged or risky agents, but it does not hard‑block them yet.

In the future, on Microsoft’s roadmap: Policy enforcement will allow organizations to require that only agents registered in the Agent 365 Registry may operate, blocking unregistered or shadow agents from running or accessing protected resources.

Do I need Agent 365 if I have Microsoft 365 Copilot?

Microsoft 365 Copilot provides AI capabilities to end-users, but it does not fully govern agents. Agent 365 is needed to ensure those agents (and any beyond Copilot) are properly managed and secured. Think of it like this: Copilot is about what AI can do; Agent 365 is about controlling what AI is allowed to do.

 

Ready to assess Agent 365 licensing and governance?

If you are planning to scale AI agents, now is the right time to review governance requirements, licensing impact, and security dependencies before general availability.

We are here to innovate with AI agents in the Microsoft universe. Contact our experts to get help with licensing AI agents to save costs and improve productivity.

 

Sources

For the announcement of Microsoft Agent 365: Unified control for enterprise AI agents, please visit: https://www.microsoft.com/en-us/security/blog/2026/03/09/secure-agentic-ai-for-your-frontier-transformation/.

General announcement of big Microsoft licensing changes, including Agent 365: https://blogs.microsoft.com/blog/2026/03/09/introducing-the-first-frontier-suite-built-on-intelligence-trust/.

Froen iwwer Lizenzéierung?
Eis Experten hunn Äntwerten.

Artikel deelen

Dësen Artikel gëtt nëmme fir Informatiounszwecker zur Verfügung gestallt. SCHNEIDER IT MANAGEMENT iwwerhëlt keng Garantien a Bezuch op d’Richtegkeet oder d’Vollstännegkeet vun den Informatiounen. Den Inhalt an d’Präisser sinn net verbindlech a leien ënner de gültege Lizenzofkommes an de Konditioune vun de Vendoren. E puer Inhalter kéinten mat Hëllef vun AI-Tools erstallt oder ënnerstëtzt gi sinn an duerno vun eiser Redaktioun iwwerpréift an editéiert ginn.

Verbonnen Artikelen