- From a Minor Issue to a Real Risk
- Agent Sprawl: When Agents Multiply Faster Than Your Controls
- What Microsoft Agent 365 Is and Isn’t
- From Inventory to Agent Map
- Four Levels of Control
- Let’s be honest: Limitations, Preview, and Licensing Costs of Agent 365
- Getting Started with Microsoft Agent 365
- Conclusion: Visibility Is the New Security
- Learn more about AI

Microsoft Agent 365 is the central management platform for AI agents in the company. The solution helps organizations make agents visible, control access, and identify risks posed by shadow AI early on. After all, the more AI agents independently access data, systems, and processes, the more important the question becomes: Who controls these agents, and who is responsible if something goes wrong?
From a Minor Issue to a Real Risk
Three developments have made this issue urgent. First: Agents take action. What began as a chatbot that provided answers now actively accesses documents, calls APIs, sends automated emails, and increasingly makes decisions on behalf of a user. Second: Agents are popping up everywhere. In the past, a handful of IT pioneers built an agent—today, all it takes is an afternoon, Copilot Studio, and a bit of curiosity for a business unit to create its own agent. Developers launch local coding agents, while others subscribe to a SaaS service, thereby bringing another type of actor into the organization. Third: Established controls are ineffective. Companies manage people, applications, and devices; there is device management and application management. Agent management, however, is rare. Agents are a new type of actor that operates somewhere in between.
Agent Sprawl: When Agents Multiply Faster Than Your Controls
Microsoft has already coined a term for this phenomenon: “Agent Sprawl.” There’s a bit of marketing hype involved, but the phenomenon itself is real: Agents multiply in a wide variety of environments; everyone knows a few they work with, but no one has a complete overview. And as their numbers grow, so do the risks.
- There’s the agent that, out of convenience, you give more permissions than it needs and which suddenly provides information that the employee isn’t even supposed to see. That’s a misconfiguration.
- Then there’s tool misuse: An agent that seems harmless at first glance moves files, closes tickets, or sends emails with poorly defined boundaries.
- There are overprivileged identities, because behind every agent is a technical account that, like many service accounts, can quickly end up with more permissions than intended.
- And finally, there are prompt-based attacks, in which an agent reads and passes on data based on manipulated inputs. These days, the media regularly reports on cases where agents even independently attack other companies.
The obvious reaction, simply blocking everything, sounds safe, but it’s a fallacy. An agent isn’t dangerous in and of itself; what matters is how it’s used. You can only control what you see. You can only secure what you understand. Any sensible approach to agents therefore begins with visibility.
What Microsoft Agent 365 Is and Isn’t
This is where Microsoft Agent 365 comes in. It is not just another platform for building agents. Agent 365 is the control layer above it—it manages, monitors, and visualizes the agents created elsewhere in your organization and regulates what they are allowed to do. The solution is built around three principles: Observe, Govern, and Secure. Observe reveals which agents actually exist. Govern controls access, checks policies, and monitors API access, for example. Secure handles data protection and threat detection and identifies which agents pose a risk.
The practical aspect of this is that Agent 365 relies on building blocks that have long been in use in most companies—Entra ID, Purview, Defender, and Intune. Each of these tools provides individual pieces of information. What was missing until now was the overarching framework that brings everything together and organizes it in a way that makes it usable.
From Inventory to Agent Map
In practice, Agent 365 is available in the Microsoft 365 Admin Center as a separate menu item, without requiring any additional installation. At its core is the Registry: a comprehensive list of all agents in the tenant, regardless of whether they were created using Copilot Studio or the Microsoft 365 Agent Builder. For each agent, you can see who created it and when, who is responsible for it, with whom it has been shared, what data it accesses, what permissions are assigned, and how often it is actually used. The concept of ownership is particularly valuable: every agent has an owner—a specific point of contact. This can be changed later, but it’s always there.
And what about third-party AI outside the Microsoft ecosystem? Through so-called Connected Platforms, additional providers can be integrated, allowing agents from other ecosystems—such as Google or GitHub Copilot—to be recognized and added to the registry. Currently, the number of supported platforms is manageable, but this is clearly just the beginning. Finally, the Agent Map visualizes which agents access which platforms—SharePoint, Microsoft 365, Copilot Studio, third-party providers—including drill-down capabilities. If an agent ever goes haywire, you can immediately see what it had access to and what might have been compromised. The accompanying dashboard also provides a management report that creates an entirely new basis for discussions with the executive board, the internal audit department, or external auditors.
Four Levels of Control
Four levels—built on familiar Microsoft tools—bridge the gap between visibility and control. Through Entra ID, every agent—just like every user—receives its own identity object that can be granted specific permissions. With Purview, you define how information is protected; data loss prevention policies are also enforced by the agents. Defender monitors behavior, blocks suspicious agents, and triggers alerts. And Microsoft Entra enforces network-level controls over which connections an agent is allowed to establish and which it is not. It is only through this combination that true control is achieved.
Let’s be honest: Limitations, Preview, and Licensing Costs of Agent 365
As promising as the picture may be, Agent 365 doesn’t solve everything, and some features aren’t ready yet. Some functions are in preview status; Microsoft itself advises against using them in production environments. In particular, there will be further changes regarding the detection of shadow AI via third-party providers. Added to this is regional availability: Some integrations—such as Purview with Windows 365 for Agents—are currently available only in the U.S. and not yet in the DACH region.
And what about the costs? Agent 365 is an extension. It’s included in the top-tier E7 plan; otherwise, it costs about $15 per user per month as an add-on, for example, to an existing E5 plan. What makes sense in your case depends on your current licensing situation and should be evaluated on a case-by-case basis.
Getting Started with Microsoft Agent 365
What does that mean in practice? The first step is to take stock: Which agents do I actually have? The second step is to clarify ownership. Who created them, who uses them, and who should I talk to if an agent is using a connector they shouldn’t be using? Third: Establish guidelines rather than imposing blanket bans—define data classifications, specify which actions an agent is not permitted to perform independently, and determine what should initially run only in a test scenario. Only then should you implement the entire setup technically using Entra, Purview, and Defender.
The most important piece of advice here is a pragmatic one: Don’t spend half a year on committee work. A massive project is the wrong approach as long as you lack experience. Instead, work with a small team to capture a snapshot in two or three days. You need a first impression and the certainty that you’ll remain able to act.
Conclusion: Visibility Is the New Security
AI agents are no longer a topic for the future; they’re already in the enterprise—often faster than governance can keep up. The reflex to ban everything actually hinders the very efficiency gains that are the reason for adopting AI in the first place. The better approach starts with visibility: first see, then understand, and finally control. Microsoft Agent 365 provides the control center for this—a unifying framework for the tools you’re already using. Not every feature is production-ready today, and not every region is covered yet. But the direction is clear, and the best time to get an overview isn’t next Monday a year from now—it’s next Monday. At COSMO CONSULT, we’re happy to guide you through this process—pragmatically, on a manageable scale, and with a focus on what really matters in your environment.
Learn more about AI
More similar blogposts:
Found what you were looking for?
Start your intelligent search now





