M365Clarity · Microsoft Scout
Microsoft Scout is Microsoft's first Autopilot agent — announced at Build 2026 and currently available in private preview through Microsoft's Frontier programme. It represents a fundamental shift in how AI works within Microsoft 365: from reactive (you prompt, it responds) to proactive (it acts autonomously in the background on your behalf).
Scout is built on OpenClaw, the open-source autonomous agent framework that became the fastest-growing open-source AI project of early 2026 before its founder joined OpenAI. Microsoft has contributed enterprise-grade identity and policy controls on top of the OpenClaw foundation.
The practical capability set is broad. Scout can read and write files in your workspace, run shell commands, control a browser, connect to your Microsoft 365 data (email, calendar, Teams, OneDrive, SharePoint), and execute tasks autonomously — including sending emails and scheduling meetings — with human approval required for sensitive actions.
Microsoft Copilot is reactive. You ask it to draft an email, summarise a document, or analyse a spreadsheet. It responds and waits for your next instruction. Each interaction is discrete.
Microsoft Scout is proactive. You tell it what you are trying to accomplish and it works continuously in the background, surfacing risks, completing tasks, and keeping work moving without waiting to be asked. Over time it builds context through a system called Work IQ — learning your priorities, your communication style, and what tasks typically follow each other in your workflow.
The distinction matters for tenant readiness because Scout is not just reading your data — it is acting on it, autonomously, as a governed identity in your directory.
Each Scout instance runs under its own governed Microsoft Entra identity — not a shared service account. This means Scout's actions are attributable to a known actor in your directory, with scoped credentials that are protected from logs and diagnostics. Scout can only reach the resources and destinations you have approved, and sensitive actions — sending email, writing files, running commands — can be configured to require explicit human approval before they proceed.
Microsoft Purview data protection policies apply to Scout in real time. Sensitivity labels and DLP policies are enforced before Scout sends or writes anything. This means Scout operates within the data governance boundaries your organisation has already configured — it does not bypass them.
The critical implication: If your tenant has not configured sensitivity labels, DLP policies, or Conditional Access — Scout will operate without those guardrails. The controls Scout respects are the controls you have deployed. An unconfigured tenant gives Scout much broader effective access than a well-configured one.
Current access requirements for the Frontier preview:
Intune being a prerequisite is significant. It means your device management baseline needs to be in place before Scout can be deployed — compliance policies, configuration profiles, and app protection policies should all be configured before bringing Scout into your environment.
Getting your tenant ready for Scout is not a new set of tasks — it is completing the configuration work that should already be in place. The areas that matter most:
Scout operates as a governed Entra identity. This means your Conditional Access policies, MFA requirements, and admin account governance directly affect what Scout can do and how it is constrained. PIM-enabled admin accounts, MFA enforcement via Conditional Access, and Entra ID Protection risk policies should all be configured before deploying an autonomous agent that inherits user permissions.
Scout respects Microsoft Purview policies — but only the ones that exist. Publishing sensitivity labels, configuring DLP policies across Exchange, SharePoint, and Teams, and enabling auto-labelling for sensitive content types ensures that Scout cannot inadvertently expose or transmit data that should be protected.
Intune is a hard prerequisite for Scout deployment. Ensure compliance policies are configured with meaningful requirements (encryption, OS version, screen lock), that BitLocker is enforced on Windows devices, and that device compliance status is being actively monitored before introducing an agent that runs at the OS level.
Scout generates its own audit trail for actions taken on your behalf. To review that audit trail effectively, you need unified audit logging enabled with sufficient retention — 90 days minimum, 1 year with E5 Purview Audit. Enable Purview Audit (Premium) if available on your licence to include Scout interaction logs in eDiscovery and compliance review.
Scout connects to Microsoft 365 as an application with delegated permissions. Reviewing existing enterprise app OAuth grants before Scout deployment — and removing any that have excessive permissions like tenant-wide Mail.ReadWrite — is good hygiene that also applies specifically to agentic AI access patterns.
M365Clarity's full scan covers all the readiness areas above — identity controls, sensitivity labels, DLP, Intune compliance, audit logging, and OAuth grant auditing — in 131 checks that take 30 seconds to run. The Copilot AI tab specifically evaluates your tenant's readiness for AI features including M365 Copilot and emerging agentic workloads like Scout.
The principle is simple: the configuration work that makes your tenant secure for human users is the same configuration work that makes it safe for autonomous agents. The agents inherit the permissions and constraints of the users they act on behalf of. A well-configured tenant bounds that risk. An unconfigured tenant does not.
M365Clarity scans 131 configuration checks including all the identity, device, data governance, and audit controls that matter before deploying autonomous AI agents in your Microsoft 365 tenant.
Free scan — no agents required →Related articles