
AI agents are already running on your Windows laptops without IT knowing. Microsoft Agent 365 is the enterprise control plane that detects shadow AI, centralises all agents, and gives IT back control. What the product does, what the 1 July licensing change means, and what you can do now.
AI agents are no longer an experiment limited to large enterprises. Developers use GitHub Copilot CLI on their work laptops. Employees install AI assistants that analyse emails and suggest action items. Project managers experiment with agents that autonomously create tasks in Planner. Many of these tools run without IT knowing anything about them, let alone having a policy in place. Microsoft calls this shadow AI, and it has become a concrete risk for every organisation managing Windows devices.
With Microsoft Agent 365, which became generally available on 1 May 2026, Microsoft introduces the first full enterprise control plane for AI agents. The product centralises visibility, management, and security of all AI agents in your environment, whether they are Microsoft Copilot agents, custom-built agents, partner agents, or unknown agents installed without IT involvement.
Agent 365 is not a feature inside an existing product, but a standalone management and security layer for AI agents. The product answers one central question that IT administrators ask with increasing frequency: which AI agents are running in our environment, what can they do, who is responsible for them, and are they behaving in line with our policies?
The platform manages three types of agents. First, delegated access agents that work on behalf of a user and inherit their permissions. Second, independent agents that operate with their own identity and their own authorisations. Third, team workflow agents that collaborate in automated chains. Each type has different security considerations, and Agent 365 makes all three visible and manageable from a single central interface.
An agent an employee installs themselves follows no least-privilege principle. It has access to everything the employee has: mailbox, SharePoint files, Teams conversations, cloud applications. If that agent processes data through an external API or an unknown MCP server, business information leaves the network without IT or Compliance knowing. That is the shadow AI risk: not the agent itself, but its invisibility.
In practice, the tools involved include OpenClaw, GitHub Copilot CLI, Claude Code, and Cursor, which appear more and more often on corporate laptops. A developer using Claude Code on their work computer may have the best intentions, but also the same permissions as their normal work account. Without policy, without visibility, and without monitoring, that is an open door for unintended data leaks or misuse.
Through integration with Microsoft Defender and Microsoft Intune, Agent 365 detects local AI agents on Intune-managed Windows devices. The Shadow AI page in the Microsoft 365 Admin Center shows which agents have been found, on which devices they run, who owns the device, and which MCP servers or cloud resources the agent connects to.
Administrators can act directly from that same interface. Rolling out an Intune policy that blocks a specific agent takes a few clicks. The block then rolls out to all managed devices within fifteen minutes to eight hours, depending on your Intune infrastructure. For agents assessed as safe, you can officially register them and link them to an owner, making them visible in the central agent registry.
An important caveat: shadow AI detection currently works only on Windows devices enrolled in Intune. Mac devices, BYOD endpoints, and contractor equipment fall outside the current scope. Microsoft has announced expansion to other platforms, but a concrete release date has not yet been confirmed.
Agent 365 is designed for three types of responsible parties. IT administrators who want to see, approve, and block agents. Security teams who want to understand risks, investigate incidents, and flag policy deviations. Business owners who are responsible for specific agents and want to report on usage and ROI.
The agent registry shows for each agent what it does, which data it can access, who the owner is, and whether it is active. Ownerless agents, agents without a designated responsible person, are automatically flagged. Inactive agents can automatically expire based on a configured policy. That prevents the situation where agents run for months in your environment after a project has ended or an employee has left.
For agents integrated via Entra Agent ID, the identity layer for AI agents in Microsoft Entra, governance has been further developed. Conditional Access policies can be applied to agent identities, restrictions on network access and external connections can be enforced, and Purview labels determine which data the agent may process or forward.
Agent 365 is not a standalone product: it is the orchestration shell around three existing Microsoft security pillars. Defender provides detection of anomalous agent behaviour, investigation capabilities, and relationship mapping showing how an agent is connected to specific users, devices, and cloud resources. Entra provides identity management for agents: authentication, authorisation, and conditional access. Purview provides information security: which data may an agent see, label, or move?
That combination is stronger than the sum of its parts. An agent that unexpectedly attempts to access files outside its scope is blocked by Purview policy and flagged by Defender. An agent that tries to connect to a non-approved external service is blocked by Entra network controls. IT does not need to manually track any of this: the policies operate automatically, based on the same labels and rules you already manage for users and data.
Agent 365 costs 15 euros per user per month as a standalone add-on, or is included in Microsoft 365 E7. The licence applies per person who manages, sponsors, or intensively uses agents. Organisations on Microsoft 365 E5 or lower pay for Agent 365 separately if they want full agent security functionality.
As of 1 July 2026, Microsoft moved a portion of the agent security functionality in Defender for Cloud Apps and Defender for Cloud into Agent 365. Organisations that on that date were using agent security features without an Agent 365 licence saw those features disabled. If you have recently lost capabilities around AI agent monitoring or security in Defender, there is a good chance you need an Agent 365 licence to reactivate them.
Three steps for every IT administrator who wants control over AI agents in their own environment. First: open the Microsoft 365 Admin Center and navigate to the Shadow AI page. Even without an Agent 365 licence, you can see which local AI agents have been found on your managed Windows devices. That is already valuable information for assessing the scale of the shadow AI problem.
Second: create an agent inventory. Which agents are officially approved and in use? Which are running without IT involvement? Which teams or employees show the most shadow AI activity? The answer determines the priority for your governance approach and helps you answer the licence question.
Third: establish an approval process for new agents. Do not wait for an incident to decide which AI tools are permitted and under what conditions. A straightforward policy covering who may register agents, which data they may access, and how ownership is secured is a solid foundation. Want advice on implementing Agent 365 or drafting an AI agent policy for your Microsoft 365 environment? Contact Zarioh.
Zarioh Digital Solutions
IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Security

Security

Security