Microsoft Agent 365 went generally available on 1 May 2026. It is the governance layer for AI agents — the control plane that answers "what agents are running, what can they do, and who is watching them?" But it only works if the right tenant configuration is already in place. This guide covers the 7 controls that determine whether your tenant is ready to deploy agents safely.
Agent 365 is not a tool for building AI agents. That is still Copilot Studio and Azure AI Foundry. Agent 365 is the management and governance layer that sits above them — the equivalent of Microsoft Intune, but for AI agents instead of devices.
It operates across three pillars:
It is available at $15/user/month standalone, or included in the new Microsoft 365 E7 SKU.
The governance layer only works if the foundations are there. Agent 365 enforces DLP, Conditional Access, and Purview audit policies — but it cannot create them. If those controls do not exist in your tenant before you deploy agents, Agent 365 has nothing to enforce.
Copilot and agent interaction logs must be explicitly enabled in the Microsoft Purview compliance portal. This is off by default. Without it, agent actions cannot be audited or investigated after an incident — and regulated industries cannot demonstrate compliance.
Where to check: Microsoft Purview compliance portal → Audit → Audit retention policies. Look for "Microsoft 365 Copilot" in the workloads list.
Agent 365 enforces Data Loss Prevention policies at runtime via Purview. But those policies must exist and must explicitly cover Microsoft 365 Copilot as a location. An agent that can access SharePoint without DLP boundaries can surface sensitive documents in ways DLP would otherwise prevent.
Where to check: Microsoft Purview → Data loss prevention → Policies. Filter by "Microsoft 365 Copilot" in the location column.
Agent 365 policy templates group settings from Entra, Purview, Defender, and SharePoint into reusable guardrails that can be applied to agents at onboarding. These templates rely on sensitivity labels to classify what content agents can access. Labels that exist but are not published to users cannot be applied by agents.
Where to check: Microsoft Purview → Information protection → Label policies. Confirm at least one policy is published to all users or the relevant groups.
Agent 365 assigns Entra Agent IDs to each deployed agent, treating agents as managed identities. Conditional Access policies will govern what those agent identities can access. If CA policies are absent, missing device compliance requirements, or not scoped to all cloud apps, agent identities inherit the same gaps.
Where to check: Microsoft Entra → Protection → Conditional Access → Policies. At minimum you need one policy enforcing MFA for all users on all cloud apps.
Agents act on behalf of the user who sponsors or activates them. A compromised account with an active agent attached is a significantly higher-risk incident — the attacker can not only access the user's data but instruct the agent to take actions. MFA enforcement is the baseline defence.
Where to check: Microsoft Entra → Users → Per-user MFA, or Entra → Security → Authentication methods. Security defaults or a CA policy enforcing MFA for all users both count.
Copilot and agents can surface any SharePoint content the sponsoring user has access to — including files shared broadly that the user may not even know exist. Unrestricted external sharing dramatically expands the data boundary agents operate within. Tighten external sharing before giving agents access to SharePoint.
Where to check: SharePoint Admin Centre → Policies → Sharing. The setting should be "Only people in your organisation" or at most "New and existing guests" with link expiry enforced.
Agent 365 integrates with Insider Risk Management adaptive protection, which can dynamically restrict agent access for users exhibiting risky behaviour — unusual data downloads, mass file access, or signs of account compromise. As agents take more autonomous actions on a user's behalf, insider risk signals become more consequential.
Where to check: Microsoft Purview → Insider risk management → Policies. If you are on E5 or E7 and have not configured this, it is an increasingly important gap as agent adoption grows.
M365Clarity scans your tenant and shows an Agent 365 readiness score across all 7 controls. See exactly which ones pass, which need review, and what to fix — in one scan.
Run a free scan →Agent 365 can still be deployed to a tenant with governance gaps — it will not block you. But the risk profile changes significantly:
| Plan | Agent 365 access | Prerequisites included? |
|---|---|---|
| Microsoft 365 Business Standard / Premium | Not included — standalone add-on | Partial (no E5 Purview features) |
| Microsoft 365 E3 | Not included — standalone add-on | Partial (no E5 security) |
| Microsoft 365 E5 | Not included — standalone add-on | Yes — all 7 controls available |
| Agent 365 standalone | $15/user/month | Depends on base plan |
| Microsoft 365 E7 | Included | Yes — full stack included |
The key insight: the Agent 365 licence buys you the governance control plane. The prerequisite controls (Purview, Entra, Defender, DLP) come from your base Microsoft 365 plan — and the completeness of those controls depends on your licence tier.
If you manage multiple Microsoft 365 tenants, the agent governance conversation is arriving faster than most clients expect. The pattern that works:
M365Clarity for MSPs scans all your client tenants and shows Agent 365 readiness scores across all 7 controls — per tenant, in one dashboard. Identify which clients need immediate attention before agents are deployed. Start an MSP trial.
Before enabling Agent 365 or expanding Copilot Studio agent deployment in any tenant, verify these 7 controls:
None of these require Agent 365 to implement. They are Microsoft 365 configuration controls that should be in place regardless. Agent 365 surfaces and enforces them — it does not replace the need for them.
Related articles