Loading Now

Microsoft Agent 365: Governing the Enterprise AI Workforce

Not just another app or chatbot, but rather a workforce.

Artificial Intelligence (AI) agents are stepping into roles across various sectors like HR, Finance, IT, Operations, Customer Service, Marketing, Engineering, Legal, and Supply Chain. Some agents tackle tasks such as drafting proposals, reconciling invoices, investigating incidents, coordinating supply chains, and ensuring compliance. They’re also working alongside humans to execute increasingly complex business processes.

This marks a significant transformation in how businesses operate. For many years, companies structured their models around human employees supported by software. Now, they’re shifting towards hybrid workforces where humans and AI agents collaborate to achieve shared business objectives.

According to Microsoft, these entities are termed Frontier Firms. Their 2025 Work Trend Index highlighted the rise of these firms, while the 2026 report pointed out a pressing issue: employees are advancing rapidly, but the organisations aren’t adapting quickly enough. IDC predicts over 1.3 billion active enterprise agents by 2028.

This is one of the most pivotal changes in enterprise tech since the rise of cloud computing.

The pressing question has transitioned from “Should we use AI agents?” to “Are we able to see, govern, secure, and manage the agents already in our businesses?”

Most organisations don’t have an AI issue; they have a visibility issue.

In recent conversations with CIOs, CISOs, Chief Digital Officers, and AI leaders, one question keeps surfacing:

“Are we able to accurately track how many AI agents we have in our organisation?”

Few feel confident enough to say yes.

AI agents are emerging from platforms like Copilot Studio, Azure AI Foundry, partner ecosystems, open-source frameworks, departmental efforts, hackathons, and citizen development initiatives. While many are addressing real business challenges, plenty are functioning outside established governance structures.

This phenomenon is what I call Agent Sprawl.

Unlike the issues of application or cloud sprawl, Agent Sprawl brings forth a new type of enterprise risk — these systems don’t just store data; they can reason, make decisions, and act, often without human intervention.

As of May 2026: Microsoft has acknowledged that this is widespread. With the launch of Agent 365, the focus is to tackle agent sprawl by identifying agents that IT was previously unaware of, especially those built on third-party platforms and operating under unmanaged credentials.

 

Traditionally, enterprise IT has overseen four main assets: people, applications, infrastructure, and data. AI agents don’t comfortably fit into any of these categories.

They have distinct identities, access enterprise systems, invoke various tools, collaborate with other agents, carry out workflows, make decisions, and adjust based on operational changes.

An AI agent is both more than software and more than a user; it is a new type of player in the enterprise.

This evolution impacts everything: identity, governance, security, compliance, observability, lifecycle management, risk management, and business responsibility now need to be reconsidered.

The risk profile of an agent is influenced by more than just code; it also involves prompts, models, data, permissions, tools, memory, orchestration, and the tasks they’re allowed to perform. An agent’s behaviour can shift dramatically over time, unlike anything mobile management or historical IT governance models have encountered.

“To effectively manage agents, it’s best to extend the infrastructure used for handling users.” — Microsoft

 

Every significant shift in technology has ultimately birthed a new operational practice.

 

Cloud computing → CloudOps

Continuous delivery → DevOps

Security → SecOps

Data → DataOps

Financial governance → FinOps

AIEnterprise AI Operations

 

This new discipline encompasses more than just deploying models or creating agents. It covers the full range of capabilities needed to manage an AI workforce responsibly:

  • Identifying every AI agent across the organisation
  • Assigning verified identities and defining clear ownership
  • Governing permissions, policies, and data limits
  • Monitoring behaviours, outcomes, and anomalies
  • Managing the entire agent lifecycle from design to retirement
  • Evaluating business performance – and acting on data insights
  • Constantly enhancing performance, cost, and risk management

 

Those who excel in Enterprise AI Operations will accelerate their AI growth with reduced risks and enhanced business value. WinWire’s AgenticOps is designed to achieve this goal.

Instead of introducing a completely new governance model, Agent 365 enhances Microsoft’s existing identity, security, compliance, and management capabilities to cover AI agents. Its aim isn’t just to manage AI but to establish a unified control system for the AI workforce.

Similar to how Microsoft Intune became the management layer for devices, Agent 365 is developing into the management layer for enterprise AI agents. Starting May 1, 2026, it is available to the public and extends beyond Microsoft platforms to oversee agents created on AWS Bedrock, Google Gemini, LangChain, and OpenAI. If an agent operates using the Model Context Protocol, Agent 365 can identify, govern, and secure it.

Main features consist of a central agent discovery and registry, Entra Agent ID, policy-driven governance, integration with Microsoft Defender, Microsoft Purview, cross-platform visibility, support for Model Context Protocol, runtime protection, and agent observability.

A control plane is essential, but it isn’t enough on its own. While technology supplies the registry, identity, policy, security, and observability, the organisation must still establish the operational model.

 

These functions are not just features; they represent the core capabilities necessary for governing AI at scale – now available in Microsoft Agent 365.

  1. Identify and register every agent — including those previously unknown. Governance begins with visibility. A centralised registry should illustrate which agents exist, their creation background, ownership, purpose, connections, and statuses such as approved, restricted, dormant, or set for retirement. Discovery should encompass both recognised and shadow AI agents.

The Agent 365 Agent Registry highlights unmanaged local agents detected automatically by the combined efforts of Microsoft Defender, Entra, and Intune, covering over 35 known agent types like coding agents and AI applications on desktops, as well as local and remote MCP servers. The registry doesn’t just log registered agents; it identifies those that IT was unaware of.

  1. Define identity as the control boundary. Each agent should have a unique, governed identity — no borrowed credentials, shared secrets, or vague delegation. An established identity ensures restricted access, Conditional Access, lifecycle management, ownership, validation, and accountability. In an agent-centric enterprise, identity represents the practical perimeter.

Entra ID Governance now extends to include partner agents integrated through the Agent 365 SDK, allowing companies to consistently apply access packages, lifecycle workflows, and least-privilege protocols across both in-house and third-party agents. If an agent is compromised, it can be contained within minutes, not weeks, complete with an audit history ready for regulatory inquiries.

  1. Regulate access, data, and actions. Merely recognising an agent isn’t sufficient. Companies need policies that outline what information an agent can access, which tools it can use, the autonomous actions it can take, where human approval is necessary, and how sensitive data is safeguarded. Governance should accompany the agent across various systems and interactions.

Purview sensitivity labels, DLP policies, and auditing now extend to agent interactions. Microsoft Defender provides context mapping for each agent, showcasing the devices it operates on, the MCP servers configured for it, the associated identities, and the cloud resources these identities can access—offering security teams the context needed for assessing potential risk before incidents occur.

  1. Monitor operational behaviour and health. Traditional telemetry only indicates whether a service is operational. Observability for agents must go further: it needs to record what actions the agent attempted, why it acted, the tools and data it utilised, whether there was any behavioural drift, if any policies intervened, and whether the result was correct. This is crucial for security responsiveness, reliability, auditing, and ongoing improvement.

Security teams can proactively execute Advanced Hunting queries in Microsoft Defender to pinpoint agents with risky configurations that could allow privilege escalation before they lead to issues. Real-time visibility means understanding the risk profile, not just activity logs.

  1. Oversee the entire lifecycle — including governance during development. Agents should be onboarded, tested, approved, deployed, monitored, updated, reassigned, suspended, and retired through a structured lifecycle management approach. Clear ownership is vital, especially when roles change, business processes evolve, or the resources supporting the agents shift.

The Agent 365 SDK, now publicly available, enables developers to incorporate monitoring, access regulations, and compliance checks directly into development processes. Agents designed on any AI platform can be enterprise-ready and compliant right from the beginning. If governance needs to happen as a separate step after development, it can often be overlooked; the SDK addresses this concern.

  1. Evaluate value — not just activity. An agent may be compliant and operationally sound but still fail to provide value. Therefore, companies need to link governance with business outcomes: adoption rates, quality, duration of processes, costs, risk mitigation, employee satisfaction, and realised ROI. Leaders should recognise which agents warrant expansion, which need redesigning, and which should be discarded.

Windows 365 for Agents, now publicly available, extends governance further: these are dedicated Cloud PCs where agents operate in completely isolated environments governed by policies, with Conditional Access enforced at the device perimeter. For companies utilising autonomous agents interacting with sensitive systems, isolated execution environments are becoming essential.

 

While technology supplies the control framework, organisations must still establish an operational model. This model should outline ownership, governance, risk management, human oversight, incident response, lifecycle management, adoption strategies, performance evaluations, cost optimisation, and continuous development.

Without this operational framework, companies risk rolling out numerous AI agents without knowing if they’re secure, compliant, or delivering tangible value. This is the function of AgenticOps — merging the technical control plane with the management practices required to continuously operate an AI workforce — not just as a one-off implementation but as a developing enterprise capability.

 

Layer

Purpose

Enterprise Outcome

AI Workforce

Agents executing and enhancing work processes

New capacity and operational leverage

Microsoft Agent 365

Monitoring, governing, and securing agents

Reliable enterprise control framework

AgenticOps

Continuously operate, optimise, and improve

Scalable, accountable AI management

Business Value Management

Prioritising, measuring, and rationalising investments

Quantifiable results and improved resource allocation

 

Model Context Protocol has become the standard integration layer across Microsoft’s technologies – found in Foundry, Agent 365, Work IQ, Fabric IQ, Teams, and Copilot. Agents developed on any MCP-compatible framework can utilise governed enterprise data and be integrated into M365 workflows without needing extensive custom work.

Leading organisations are already strategising beyond just deployment. The lifecycle of an AI agent closely mirrors that of an employee:

 

Design

Build

Register

Approve

Deploy

Monitor

Optimise

Retire

 

Seeing agents as long-term assets, rather than temporary projects, will characterise advanced AI organisations. Each phase requires precise processes: design with achievable business outcomes in mind, build with governance in place, register with identifiable ownership, approve through structured controls, deploy with monitoring from day one, continuously improve based on measurable outcomes, and retire agents with similar rigor as onboarding.

This focus on lifecycle management also changes how organisations fund and resource AI initiatives. Agents aren’t one-off project items; they’re operational assets that demand continuous management — and effective oversight is where the competitive edge lies.

If you’re considering Agent 365, it’s crucial to evaluate its current capabilities, not just wait for it to become fully developed. Ask yourself, which features are currently available? Here’s a summary as of July 2026:

 

Generally available

Public preview (June–July 2026)

In development

Overview dashboard & central registry for agents

Real-time alerts and blocking through Intune and Defender

Agent 365 for GCC and sovereign cloud segments

Entra Agent ID and policies for limited access rights

Risk scoring for local agents through Defender (35+ types)

Governance for multi-agent orchestration

Purview DLP, sensitivity labels, and auditing functions extended to agents

Mapping context from Defender regarding devices and cloud resources

Enhanced integrations for Fabric IQ and Work IQ

Continuous threat detection and immediate blocking via Defender

Entra ID Governance offerings for agents via SDK

 

Agent 365 SDK (available since Build 2026) — compliance functionality embedded into developer workflows

Windows 365 dedicated Cloud PC for agent workloads governed by policy

 

Advanced Hunting capabilities in Defender for proactive identification of agent-related threats

Discovery of MCP servers across managed devices running Windows or macOS

 

 

This development means you can initiate a meaningful governance programme today with the available capabilities. Preview features highlight the strengthening of security measures and the discovery phase for local agents — crucial for companies with significant RPA or developers’ agents on managed endpoints.

This progression illustrates a larger shift in what enterprise AI now signifies — and where the next competitive advantages will emerge:

 

Era

Enterprise Focus

Key Outcome

Copilot Era

Assist individuals

Boosted productivity

Agent Era

Execute workflows

Enhanced autonomy

AI Workforce Era

Coordinate human-agent teams

Redesign of organisational structures

AI Operations Era

Governance, security, measuring, and optimisation

Trusted scaling and sustained value

 

Agent 365 is the foundation for this latest chapter. Companies that prioritise the discipline of AI Operations now are establishing the competitive base that will be reflected in industry reports in the next couple of years.

Before broadening AI across their enterprises, leadership teams must be able to address a few crucial questions:

▸  Do we maintain a dependable list of every AI agent functioning within our setup, regardless of authorisation?

▸  Is there a clear identifiable owner for each agent, along with a defined purpose and an established scope of operation?

▸  Are identities and data access consistently managed with least privilege and policy — rather than assumed?

▸  Do we have the capability to observe interactions, investigate issues, clarify each autonomous decision, and show compliance?

▸  Are there lifecycle controls to approve, update, suspend, reassign, and retire agents?

▸  Do our developers have mechanisms in place to naturally incorporate governance in agent creation — or is governance a separate step that may be easily overlooked?

▸  Can we link every active agent to adoption, expenses, risks, and measurable business results?

▸  Is there a transparent operational structure that spans IT, security, data, legal, risk, and business accountability?

 

These are no longer just technical queries; they are strategic questions for executive leaders.

 

Organisations that tackle these issues honestly — rather than checkboxing them on a slide — tend to emerge in analyst reports as Frontier Firms. They achieve this not necessarily by moving the quickest, but because they avoid issues beforehand.

The widespread use of agents is occurring regardless of readiness. The platform for managing this transition is now widely available and rapidly evolving. What remains uncertain is whether organisations choose to utilise it proactively or await its discovery during a crisis.

The initial generation of enterprise AI was about deployment. The next will concentrate on its operations.

Success will not merely belong to those companies that craft the most agents but rather to those that build the strongest governance, operation, measurement, and continuous enhancement capabilities around their AI workforce.

Microsoft Agent 365 offers the enterprise control framework necessary for managing an AI workforce. Companies that marry this control structure with a dedicated Enterprise AI Operations framework will shape the next generation of Frontier Firms.

Every enterprise is forging a new workforce. The strategic question lies in whether this workforce will develop as a collection of disconnected experiments or as a transparent, secure, governed, and continuously optimised source of business value.

 

Some organisations will scale quickly and uncover the sprawl issues during audits or, worse, through unnoticed data exposures that are difficult to rebuild. Others will establish a control system early and grow gradually — receiving fewer headlines either way. The true difference becomes apparent when something goes awry, determining if their governance withstands the test or collapses.

 

The future will not belong to those who just deploy more AI, but to those who manage it proficiently.

 

 

▸  Learn more about Microsoft Agent 365  —  learn.microsoft.com/en-us/microsoft-agent-365/overview

▸  Microsoft Agent 365: The control platform for AI agents  —  microsoft.com/en-us/microsoft-agent-365

▸  Microsoft Agent 365 is generally available (May 1, 2026)  —  microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available

▸  What’s new in Agent 365 — May 2026  —  techcommunity.microsoft.com/blog/agent-365-blog

▸  What’s new in Agent 365 — June 2026  —  techcommunity.microsoft.com/blog/agent-365-blog

▸  Insights from Microsoft Build 2026: Securing code, agents, and models  —  microsoft.com/en-us/security/blog/2026/06/02/microsoft-build-2026

▸  Agent 365 SDK overview  —  learn.microsoft.com/en-us/microsoft-agent-365/developer/agent-365-sdk

▸  Understanding Microsoft Entra: Governing agent identities  —  learn.microsoft.com/en-us/entra/id-governance/agent-id-governance-overview

▸  Comprehending Microsoft Entra: What constitutes agent identities?  —  learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities

▸  2025 Work Trend Index: The rise of the Frontier Firm  —  blogs.microsoft.com/blog/2025/04/23/the-2025-annual-work-trend-index

▸  2026 Work Trend Index: The dynamics of agents, human roles, and preparation within organisations  —  microsoft.com/en-us/worklab/work-trend-index/agents-human-agency

▸  Updates in observability featured at Build 2026  —  techcommunity.microsoft.com/blog/azureobservabilityblog

Share this content:


Discover more from Qureshi

Subscribe to get the latest posts sent to your email.

Discover more from Qureshi

Subscribe now to keep reading and get access to the full archive.

Continue reading