Craig Stanley
Home / Risk / Governance stack / Agent 365 in plain terms

Agent 365 in plain terms

What Microsoft Agent 365 does, which parts come with ordinary Microsoft 365 plans, which need E7 or the add-on, and where it fits in a risk register.

· 3 min read · Craig Stanley
In short, explained

As companies get more computer helpers, someone needs a list of them all and a way to switch off a bad one. Agent 365 is Microsoft's list and switchboard.

Agent 365 is Microsoft's control centre for AI agents. It keeps a registry of every agent in the organisation, lets admins approve, block or reassign them, and with the paid version adds monitoring, policy templates and security controls. It answers the basic question: what agents do we have, and who owns each one?

Agent 365 is the agent control plane (observe, govern, secure) built on the registry in the Microsoft 365 admin center, with Entra Agent ID for identity. Inventory, basic governance and rule-based lifecycle actions come with Microsoft 365 plans; policy templates, observability, tool access control, risk signals and Purview/Defender/Intune agent features need E7 or the Agent 365 subscription.

What it is

Microsoft describes Agent 365 as giving organisations "the ability to observe, govern, and secure the growing number of agents". Its service description calls it "a centralized control plane for AI agents" that works with agents built on Microsoft platforms and with third-party agents.

The centre of it is the agent registry in the Microsoft 365 admin center: a single inventory of agents in the organisation. Microsoft says it's converging the registry experiences that used to appear in several portals under Agent 365, with Microsoft Entra still providing the identity layer through Agent ID.

What comes with ordinary plans

This is the part I find most useful to know, because it changes what's possible without a new purchase. Microsoft's service description lists these as included with Microsoft 365 Enterprise, Business, Education and Frontline plans:

Included with Microsoft 365 plans
An inventory of agents across the organisation in the registry
Basic governance actions: publish, deploy, block, delete, approve, assign to users or groups, reassign owner
Rules that automate lifecycle actions based on conditions
Syncing agents from external platforms into the registry

Microsoft also says that viewing all agents doesn't need a specific licence, only an admin role such as AI Reader, which it recommends as the least-privileged option.

What needs E7 or the add-on

The same table lists features that need Microsoft 365 E7 or the Agent 365 subscription. They include policy templates, observability and monitoring of agent activity, tenant-wide control over which tools agents can use, and a range of Entra, Purview, Defender and Intune features applied to agents, such as conditional access, audit and eDiscovery of agent interactions, data loss prevention and insider risk management. The Risks column and Security tab in the registry also need E7 or Agent 365.

Agent 365 is sold as a standalone subscription and is included in Microsoft 365 E7.

Where it fits in a risk register

In Start a risk register from the decision inventory, every row needs an owner. For agents, the registry is the natural source of truth for who owns what. If an agent in the registry has no owner, or an owner who has left, that's a finding before any risk scoring starts.

The basic governance actions are also controls in their own right. Blocking an agent is the "stop" route for a misbehaving agent. Assigning an agent only to a named group is a way of limiting its reach while it's piloted.

A worked example

This example is illustrative. A 2,000-person organisation without E7 opens the registry for the first time and finds 140 agents.

FindingCountAction using included features
Agents with an owner who has left12Reassign owner or block
Agents shared with everyone but used by fewer than 5 people35Reassign to a smaller group
Agents nobody in IT knew about, built in Agent Builder60Add to the decision inventory if they influence decisions
Third-party agents4Check contracts and data access

None of this needs the paid features. The paid features would add monitoring of what those agents actually do, which matters most for the handful that make or shape real decisions.

What I'm still checking

Microsoft's feature table is detailed but changes often, and a note on the same page says Agent 365 meets FedRAMP High controls with final authorisation pending, which suggests the service is still settling. I'd re-read the table before any licensing decision.

Sources

Read next

A question to take awayWho gets told, and how fast, when a decision model starts drifting?

About me

Craig Stanley

Microsoft AI consultant and technical architect, based in Whitley Bay. Over the last few years I've delivered Microsoft 365 Copilot, Copilot Studio agents, Microsoft Foundry (formerly Azure AI Foundry) work and governance for UK public sector and financial services organisations.

What interests me is the decision underneath the tool: what it costs, what it risks, and whether a small, transparent model can make it better. I write the methods up here and on Substack so anyone can use them.

I write this site to learn in public: explaining each idea simply is how I check I understand it. Why I write this site.

Find me