Microsoft Agent 365 is Microsoft’s governance and management layer for AI agents: a control plane that gives an organization a registry of every agent operating in its environment, identity-based access control over what each agent can touch, and monitoring of what agents actually do. Microsoft’s framing is blunt and useful: agents should be managed like employees, with an identity, scoped permissions, oversight, and offboarding, rather than left as ungoverned scripts with superpowers.
If your organization is rolling out Microsoft 365 Copilot and starting to build agents in Copilot Studio, Agent 365 is the answer to the question your security team is about to ask: who is keeping track of all of these?
Why AI agents need governance at all
A Copilot chat answers a person who is present, authenticated, and accountable. An agent is different in kind: it acts on its own trigger, touches data when nobody is watching, and multiplies. One team builds an agent to triage invoices, another builds one to summarize support tickets, a third buys a vendor product with agents embedded in it. Within a year, a mid-sized organization can plausibly have dozens of agents holding real permissions.
Ungoverned, that produces the same failure pattern IT has seen twice before, with SaaS sprawl and with Power Platform “citizen development,” but with higher stakes:
- Shadow agents. Nobody can list what agents exist, who created them, or what they can access.
- Over-permissioned agents. An agent granted broad access “to make it work” retains that access forever.
- Orphaned agents. The employee who built an agent leaves; the agent keeps running with their permissions.
- No audit trail. When something goes wrong, there is no record of which agent did what, when, on whose authority.
Every one of these is an identity and governance problem, not an AI problem, which is exactly the ground Agent 365 is built on.
What Agent 365 includes
Agent 365 applies the management stack organizations already use for people to agents instead:
- A registry. A central inventory of agents in the tenant, including agents built in Copilot Studio and agents from third-party platforms, so “how many agents do we have” has an answer.
- Identity and access control. Agents get identities through Microsoft Entra, which means scoped permissions, conditional access, and the ability to disable an agent the same way you disable a compromised account.
- Monitoring and visualization. Visibility into what agents are doing and how they interact with data and with each other.
- Security integration. Agent activity feeds the Microsoft security stack, including Defender, so agent behavior is watched by the same operation that watches users and endpoints.
- Lifecycle management. Onboarding, review, and retirement, so agents leave the environment when their purpose or their owner does.
Agent 365 vs. Copilot Studio: what each does
The names invite confusion, and the distinction is simple:
| Copilot Studio | Agent 365 | |
|---|---|---|
| Job | Build agents | Govern agents |
| Users | Makers and developers | IT, security, and compliance |
| Question it answers | ”How do we create an agent that does X?" | "What agents exist, what can they access, and who is accountable?” |
| Scope | The agents you build | Every agent in the tenant, built or bought |
You will likely need both: Studio is where agent value gets created, and Agent 365 is what makes scaling that creation survivable. We cover the build side, including Copilot Studio and where agents fit in a Microsoft 365 environment, on our Copilot Agents and Governance page.
What Agent 365 costs
Microsoft lists Agent 365 as a per-user add-on at $15 per user per month, alongside Microsoft 365 Copilot at $30 per user per month. Microsoft has also introduced a Microsoft 365 E7 bundle at $99 per user per month that packages Microsoft 365 E5, premium Copilot capability, and Agent 365 together, which changes the licensing math for organizations already on or considering E5.
Two practical notes on the pricing. First, Microsoft’s AI licensing is moving quickly, so verify current terms before budgeting. Second, the real cost question is usually not the add-on but the sequencing: paying for governance tooling before you have agents is premature, and scaling agents before you have governance is how the sprawl scenarios above happen. The window to get this right is exactly when agent-building starts.
How to prepare before agents scale
Whether or not you license Agent 365 on day one, the preparation is the same, and it is work most organizations need anyway:
- Get identity clean first. Agent governance rides on Entra. Stale accounts, weak conditional access, and unscoped permissions get inherited by agents.
- Decide who approves agents. A lightweight intake, an owner per agent, a review cadence. Policy before tooling.
- Label and protect data. Agents surface whatever they can reach. Data governance gaps that were tolerable with human users become visible fast, the same lesson Copilot deployments already teach.
- Start with a registry, even a manual one. If agents already exist in your tenant, list them now. Migrating a known inventory into Agent 365 is easy; discovering an unknown one is not.
- Put agent activity in front of your security operation. Someone has to actually read what the monitoring produces. Security operations has to own agents the way it owns endpoints.
Where Virteva fits
Virteva is a Microsoft Solutions Partner delivering Copilot agent and governance services: readiness assessment, Entra and data-protection groundwork, Copilot Studio agent development, and the governance model, including Agent 365, to run agents safely at scale. We also help organizations sequence the licensing decisions across Copilot, Agent 365, and the E7 bundle so governance arrives with the agents rather than after them.
If agents are appearing in your tenant faster than answers about them, our advisory team can inventory what exists today and design the governance model before the count doubles.
Frequently asked questions
What is Microsoft Agent 365? Microsoft Agent 365 is a governance and management layer for AI agents in an organization’s environment. It provides a central registry of agents, identity-based access control through Microsoft Entra, monitoring of agent activity, and integration with Microsoft’s security stack, so agents are managed with the same discipline as employees.
Is Agent 365 the same as Microsoft 365 Copilot? No. Microsoft 365 Copilot is an AI assistant that helps individual users work inside apps like Outlook, Teams, and Excel. Agent 365 does not assist users; it governs the autonomous AI agents an organization builds or buys, providing inventory, access control, and oversight.
What is the difference between Copilot Studio and Agent 365? Copilot Studio is the tool for building agents. Agent 365 is the control plane for governing them: a registry, permissions, monitoring, and lifecycle management across every agent in the tenant, including ones built outside Studio. Organizations scaling agent development typically need both.
How much does Microsoft Agent 365 cost? Microsoft lists Agent 365 at $15 per user per month as an add-on, with Microsoft 365 Copilot at $30 per user per month, and a Microsoft 365 E7 bundle at $99 per user per month combining E5, premium Copilot capability, and Agent 365. Microsoft’s AI licensing changes frequently, so verify current pricing before budgeting.
Do we need Agent 365 before building our first agent? Not necessarily on day one, but the groundwork it depends on, clean identity in Entra, data labeling, and an owner-and-approval model for agents, should be in place before agent development scales. Retrofitting governance onto dozens of unknown agents is far harder than starting with an inventory of three.