,allowExpansion)
How to Govern AI Agents at Scale: A Practical Guide to Agent 365 for IT Leaders
AI agents are spreading faster than the controls around them. A few months ago, an enterprise might have had a handful of Copilot Studio bots. Today the same enterprise has Copilot Studio agents, Foundry agents, custom Azure OpenAI agents, third-party agents from partner platforms, and a growing number of agent-built-by-agent variants nobody planned for. The agents work. Nobody is sure who owns them, what they can touch, or how to switch one off.
Governing AI agents at scale is the new IT job. Microsoft's answer is Agent 365, a control plane that gives IT leaders inventory, identity, observability, security, and cost management for every agent in the estate. Implemented well, Agent 365 turns shadow AI into a managed asset class.
What is Agent 365?
Agent 365 is Microsoft's unified control plane for observing, governing, and securing AI agents across Microsoft Copilot Studio, Azure Foundry, and third-party runtimes. The platform became generally available on May 1, 2026 and is available standalone or as part of the Microsoft 365 E7 package.
The need is real. McKinsey's State of AI 2025 found that 23 percent of organizations are already scaling agentic AI in at least one business function, and an additional 39 percent are experimenting. That puts 62 percent of enterprises on the agent curve, with operational maturity to govern them lagging.
Agent 365 brings five core capabilities together in one place:
Agent inventory and registry that discovers sanctioned, third-party, and shadow agents
Identity and access control through Microsoft Entra Agent ID, with conditional access and lifecycle management
Observability and monitoring built on OpenTelemetry standards, surfaced in the Microsoft 365 admin center
Security and compliance via integration with Microsoft Defender and Microsoft Purview
Cost management for token consumption, compute usage, and per-agent attribution
The four governance domains Agent 365 covers
Effective AI agent governance covers four domains. Agent 365 has a corresponding capability for each, but the domains are concepts every IT leader needs to understand independent of the product.
1. Identity and access
Every agent needs an identity, the same as every user. Microsoft Entra Agent ID gives each agent a managed identity with least-privilege permissions, conditional access policies, and a defined lifecycle. An agent without identity is an agent that cannot be revoked, audited, or scoped. Pair the Agent ID model with the broader security and identity practices the enterprise already runs.
2. Activity and observability
Agents act continuously, asynchronously, and across systems. Activity logging has to capture what the agent did, which tools it called, what data it accessed, and what output it produced. Agent 365 observability builds on OpenTelemetry, surfaces in the Microsoft 365 admin center, and supports declarative agents out of the box. A modern data and AI platform gives the activity stream a real home for analysis and retention.
3. Policy and compliance
Agents must respect data classification, residency, content safety, and regulatory boundaries the same way users do. Agent 365 integrates with Microsoft Defender for risk detection and Microsoft Purview for data governance. Policy enforcement is centralized, not bolted onto each agent. A formal AI governance framework makes the policy layer reusable across agent platforms.
4. Cost and lifecycle
Token consumption, compute usage, and agent sprawl produce real bills. Cost management in Agent 365 tracks usage per agent and per department, with quotas and alerts. Lifecycle management covers retirement of unused agents, version control, and certification readiness. Without this domain, agent cost grows quietly.
How to roll out Agent 365 in your enterprise
A working rollout takes five steps. The order matters: discovery comes before policy, and policy comes before scaling adoption.
1. Inventory every agent already running
Agent 365 starts with discovery. Run the inventory across Copilot Studio, Azure Foundry, M365 Copilot, and the third-party runtimes departments have signed up for. The first inventory is almost always larger than expected. Capture owner, purpose, data accessed, and tools called for each agent.
2. Assign identities and access scopes
Issue a Microsoft Entra Agent ID for every discovered agent. Define least-privilege scopes based on the inventory data. Agents that touch sensitive data get conditional access. Agents without a clear owner get flagged for retirement. The step turns shadow agents into governed ones without breaking what works.
3. Instrument observability for every agent
Declarative agents come with observability out of the box. Custom engine agents and Agent 365-enabled agents need the observability SDK installed. Set up the standard dashboards in the Microsoft 365 admin center, and route the OpenTelemetry stream to the SIEM and analytics tools the team already uses. Disciplined AI app innovation practices keep this step lightweight.
4. Apply policy through Defender and Purview
Connect Agent 365 to Microsoft Defender for risk detection and Microsoft Purview for data governance. Configure data loss prevention rules that apply to agent actions the same way they apply to user actions. Set content safety filters on agent outputs. The goal is one policy layer that covers users and agents together.
5. Establish a steady-state operating model
Define who owns the agent inventory (a central platform team), who reviews exceptions, and how new agents get certified. The Microsoft 365 admin and security teams need a shared cadence, not separate workflows. Build agent activity review into the same operations rhythm that covers users and apps.
Common mistakes when governing AI agents at scale
Three mistakes show up consistently in early Agent 365 rollouts. Each is preventable with a few hours of design before deployment.
1. Treating agents as software, not as identities
Agents that act on behalf of users need an identity, a permission scope, and a lifecycle, the same as any service account. Teams that skip this and treat agents as "scripts that call APIs" have no way to audit, revoke, or scope what the agent does. The first agent that touches production data with no identity is the agent that becomes a postmortem.
2. Building parallel governance instead of unifying
Some teams build a separate governance stack for agents, parallel to the one they already run for users and apps. The result is duplicate identity stores, duplicate policy engines, and duplicate alerts. Agent 365 is designed to fold agents into the existing admin center, Defender, and Purview workflows. Use the existing tools.
3. Ignoring cost until the bill arrives
Agent token and compute costs grow quietly. Teams that defer cost management find themselves in a finance review with no per-agent attribution. Turn on Agent 365 cost management on day one, set departmental quotas, and review monthly. The cost data is also what justifies the next wave of agent investment.
Bring agent governance into the operating model you already run
The hardest part of Agent 365 is not deployment. The hard work is treating agents as a first-class identity class inside the operating model your security and platform teams already use. Pick one agent in your estate today (the one nobody owns, the one with broad permissions, the one that talks to production) and run it through the four domains above. If you want a second opinion on the rollout, start a conversation with Valorem Reply.
Valorem Reply has an 8-week Agent 365 Governance Foundation engagement that helps enterprises secure and operationalize AI agents across their Microsoft 365 environment by establishing a centralized control plane. Click here to learn more and get started.
Discover how Microsoft Agent 365 helps organizations observe, govern, and secure AI agents with the same confidence and control used to manage users - Download eBook.
Watch our webinar - Scaling AI Agents with Confidence: Enterprise Adoption with Agent 365