New Agent 365 controls for Microsoft admins
Govern every AI agent running across your organization with Agent 365. Track agents from Microsoft, Amazon, Google, and Salesforce in one registry, sync in agents you're already running on AWS Bedrock, Google Cloud, Databricks Genie, and Anthropic Claude, and lock down shadow AI with default blocks and Execution Container isolation.
Agent 365 inspects your environment for every agent Microsoft and partners have registered, then layers control on top. Reusable security policy templates apply Conditional Access, Access Packages, and Custom Security Attributes the moment you approve an agent, Tools governance blocks risky MCP servers and connectors org wide, and the Adoption Dashboard breaks down usage by group, job function, and license type for every manager in your org.
Jeremy Chapman, Microsoft 365 Director, shares how to bring every agent in your organization under one governed registry, and how to shut down shadow AI before it ever compromises your environment.
👥 Who it's for:
IT admins, security engineers, and identity teams governing AI agents across Microsoft 365, Entra, Purview, Defender, and Intune; solution architects designing agent access, tools, and security policy at scale; developers and DevOps teams building and registering agents and custom MCP servers in Copilot Studio, Agent Builder, and Foundry; and team leads, finance, and IT leaders tracking agent adoption, usage, and spend across the organization.
⏱️ Chapters:
00:00 Why you need an AI agent control plane
02:00 See every AI agent across your environment with the unified agent registry
02:50 Track local AI activity with OpenTelemetry and the Agent Map
03:16 Sync AI agents from AWS Bedrock, Google Cloud, Databricks and Claude with Registry Sync
03:55 Approve, publish and block AI agents across your organization
04:42 Manage MCP servers, plugins and connectors with Tools governance
05:18 Apply reusable security policy templates across Entra, Purview, Defender and Intune
06:06 Block shadow AI and isolate local agents with Microsoft Execution Containers
06:23 Track agent adoption and usage with the Agent 365 dashboard
07:06 Set spending limits and cost alerts for AI agents
08:02 Monitor AI agent costs and buy prepaid credits
09:07 Get started with Agent 365 today
Agent 365 gives you one place to govern every AI agent running across your organization, no matter where it was built or who owns it. In this demo, the unified agent registry surfaces agents from Microsoft Foundry, Copilot Studio, Agent Builder, and SharePoint, alongside agents from Amazon, Google, and Salesforce, each with its identity, owner, permissions, and usage history attached. Local AI running on managed devices shows up too, logged through standardized OpenTelemetry and mapped visually in the Agent Map so you can trace connections between agents, people, data, and tools. Registry Sync pulls in agents you're already running on AWS Bedrock, Google Cloud, Databricks Genie, and Anthropic Claude with nothing more than a connection string, and from the same registry you approve agents for broader use, publish or pin them to specific groups, automate ownership handoffs when an employee leaves, and block any agent you don't want in production.
From there, Agent 365 puts you in control of what agents can touch and how they're secured. The Tools view gives you one place to see every MCP server, plugin, and connector your agents rely on, block the risky ones, and approve or reject new tool requests as they come in. Reusable security policy templates apply Conditional Access, Access Packages, and Custom Security Attributes the moment you approve an agent, drawing on native signals from Microsoft Entra, Purview, Defender, and Intune so your identity, data security, SecOps, and device teams enforce the same controls. Shadow AI running as unsanctioned local agents gets blocked by default through Intune policy and isolated from user sessions with Microsoft Execution Containers. Team leads and managers track adoption and usage in the Agent 365 Dashboard, filtered by group, organization, job function, or license type. IT and finance teams set monthly spending limits, per user budget caps, and weekly usage alerts for Copilot Cowork and the Work IQ API, and can pre purchase discounted credits to keep spend predictable.
🔗 Related links:
► Get started at https://aka.ms/agent365
► Unfamiliar with Microsoft Mechanics? Microsoft's Official Video Series for IT
— Subscribe https://www.youtube.com/c/MicrosoftMechanicsSeries
— Microsoft Tech Community: https://techcommunity.microsoft.com/t5/microsoft-mechanics-blog/bg-p/MicrosoftMechanicsBlog
— Podcast: https://microsoftmechanics.libsyn.com/podcast
►Join us on social:
— https://twitter.com/MSFTMechanics
— https://www.linkedin.com/company/microsoft-mechanics/
— https://www.instagram.com/msftmechanics/
— https://www.tiktok.com/@msftmechanics
Published on:
Learn moreWe can help you with New Agent 365 controls for Microsoft admins
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Made for tech enthusiasts and IT professionals. Expanded coverage of your favorite technologies across Microsoft; including Office, Azure, Windows and Data Platforms. We'll even bring you broader topics such as device innovation with Surface, machine learning, and predictive analytics.
Related posts
Windows 365: Five Years In, See What's New
An AI agent works inside your Windows 365 Cloud PC from a Teams chat on your phone — finding downloaded files, editing documents, and drafting...
Build your first Power App from data in seconds
Build a fully working model-driven app from your existing Dataverse, SharePoint, or SQL data in under a minute — screens, navigation, and form...
Microsoft Entra Suite hands-on tour of identity and network access protections
Unify identity and network access controls. Enforce least privilege access across every app and resource. Wire lifecycle workflows directly to...
New agentic platform in Dynamics 365 for Sales and Service
Qualify a lead, close a case, or walk into a renewal meeting fully briefed, all from the sales and service agents built into Dynamics 365. Ask...
Tokenomics | The new AI currency & your options explained
Control what you're billed on. Tokens are the currency of AI, and how you design your app determines how many you spend. Compress conversation...
Deploy Windows updates to counter AI-discovered threats
The speed that AI can now discover and exploit vulnerabilities means that our defenses also need to adjust. For the devices that you manage wh...
Zero Trust security for AI agents
Apply Zero Trust controls to every AI agent in your environment across identity, tool usage, and data access. Extend Conditional Access in Mic...
Secure containers from code to runtime | Microsoft Defender
Secure containerized apps end-to-end using Microsoft Defender for Cloud. Correlate cross-cloud attacks into a single incident, catch runtime t...
Find and fix app issues - Azure Copilot Observability Agent
Cut through alert noise and move from detection to root cause using the Azure Copilot Observability Agent. It autonomously investigates incide...
Build Agent Architecture using AI Landing Zones
Build enterprise-ready AI agents that scale without sacrificing security or control using Microsoft Azure. Establish a shared Governance Hub t...