HomeCybersecurityMicrosoft Agent 365 reaches general availability for AI agent oversight

Microsoft Agent 365 reaches general availability for AI agent oversight

Microsoft has made Agent 365 generally available for commercial customers, positioning it as a management and security layer for organisations trying to keep track of AI agents across workplace systems.

The launch comes as companies adopt agents through productivity suites, developer tools, cloud platforms and software-as-a-service applications. For IT, security and risk teams, the practical issue is no longer whether agents will appear in the business. It is how to find them, understand what they can access and apply controls before they become another unmanaged technology layer.

Agent 365 is designed to give organisations a single place to observe, govern and secure agents that act for users, as well as agents that operate with their own credentials and permissions. Microsoft says the service is intended to work across local devices, software services and cloud environments while fitting into administration and security workflows that many enterprise teams already use.

A control layer for agent sprawl

A major buyer concern is the rise of so-called shadow AI, where agents are installed, built or used outside approved controls. Microsoft describes this as a growing risk because agents may be able to invoke tools, access files, connect to services or perform work at a pace that is difficult for human reviewers to follow manually.

The company is adding discovery and management features through Microsoft Defender and Intune. These are intended to help organisations identify local AI agents running on Windows devices, starting with OpenClaw and expanding to tools such as GitHub Copilot CLI and Claude Code.

Microsoft says customers in its Frontier programme can see whether OpenClaw agents are being used, identify the devices where they run and apply Intune policies aimed at blocking common ways the tool operates. A local agent registry is also being made available through Defender and Intune, giving endpoint management and security teams a shared inventory of discovered agents.

Some planned capabilities remain preview-oriented rather than fully settled. Microsoft has said additional asset context mapping is expected for public preview in June 2026, including links between agents and the devices they run on, configured MCP servers, associated identities and cloud resources those identities can reach. That roadmap detail should be treated as Microsoft’s stated plan, rather than an independently proven production capability.

If delivered as described, the feature would help security teams assess exposure, investigate file access and network behaviour, and create custom detections using endpoint context. For buyers, the key question will be how much of that context is available out of the box, how well it works across mixed environments and whether it reduces investigation time in real incidents.

Cloud and SaaS coverage widens

Agent 365 is not limited to Microsoft-built agents. Microsoft says the service covers agents created in Microsoft 365 Copilot, Teams, Copilot Studio and Foundry, along with partner-built agents and selected SaaS integrations.

Named ecosystem integrations include Genspark, Zensai, Egnyte and Zendesk. Microsoft has also pointed to agent factory providers such as Kasisto, Kore and n8n. The commercial pitch is straightforward: organisations should be able to bring more agents into a central inventory without asking every internal IT or security team to build one-off integrations.

Agent 365 also now includes public preview support for registry synchronisation with AWS Bedrock and Google Cloud connections. Microsoft says this is intended to let IT teams discover and inventory cloud agents across those platforms. Basic lifecycle governance actions, such as starting, stopping and deleting agents, are expected to follow.

For enterprises already using multiple AI-builder platforms, that multicloud angle matters. Agents may be created by development teams, business units or vendors, and they may connect to data stores, APIs and identity systems outside the Microsoft stack. A useful control plane will need to show not only that an agent exists, but also what it can reach and which team owns it.

Network controls and managed agent environments

Microsoft is also extending Entra network controls to Copilot Studio agents and to agents running on user endpoint devices, including local agents such as OpenClaw. Microsoft says those controls are available as part of the general release of Agent 365.

The controls are meant to help security teams inspect traffic at the network layer, restrict outbound connections to approved destinations, filter risky file movement and block prompt-based attacks before they trigger harmful actions. As with any security control, buyers should validate the coverage against their own agent types, endpoint estate and network architecture before treating it as comprehensive protection.

The release is also tied to Windows 365 for Agents, which is in public preview in the United States. The service provides Cloud PCs intended for agent workloads and managed through Intune. The idea is to give agents a controlled Windows environment where they can interact with applications, browsers, files and enterprise systems under familiar identity and device policies.

With Agent 365, organisations can see agents connected to those cloud systems through the Microsoft 365 admin centre. Microsoft is positioning the combination as a path from basic visibility and governance toward running agent workloads in managed production settings.

For CIOs and CISOs, the main value will depend on execution rather than branding. Agent 365 addresses a real operational gap: agents are spreading across endpoints, SaaS tools and cloud platforms faster than many governance models were designed to handle. The buying case will rest on whether Microsoft can provide accurate discovery, useful context, enforceable controls and broad enough ecosystem coverage to reduce the work required from already stretched IT and security teams.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

POPULAR TAGS

- Advertisment -