Skip to Content
Cowork (Agentic AI)Agent Governance Guide

Governing AI Agents in Microsoft 365

TL;DR: Govern agents by finding them first. Inventory registered and unmanaged agents, give each a named human sponsor, then check tools, data policies, Work IQ access and computer use. The read-only skills below produce evidence of what is configured. They do not certify anything.

This is a guide, not a skill. It follows the order an administrator would work through, using what Microsoft Learn documents for Microsoft Agent 365, Microsoft Entra Agent ID and Microsoft Copilot Studio. Where Learn is silent, this guide says so rather than guessing. Several capabilities are in preview, and Learn says preview features can change, so recheck status before relying on it.

What is an AI agent, and why does it need governing?

Microsoft Learn defines an agent as an AI-powered entity that performs tasks autonomously or semi-autonomously, using instructions, context, knowledge sources and tools. Governing agents in Microsoft 365 means controlling how they are accessed, published, deployed and managed, so the agents and the data they use stay secure and compliant.

Learn names three challenges that this guide is organised around:

  • Applying consistent policy to every agent, regardless of where it was built.
  • Balancing maker freedom with central oversight.
  • Finding and retiring low value or ownerless agents before they create risk or cost.

Where do you see every agent in the tenant?

Microsoft Agent 365 registry, in the Microsoft 365 admin centre, is the central list of agents available to your organisation. Learn places it under Agents, All agents, Registry. It shows total agents, agents without owners and unmanaged agents, and it can export the inventory to CSV for analysis.

Registry itemWhat Learn says
Agent typesMicrosoft agents, external partner-built agents, agents published by your organisation, and agents shared by their creator
Unmanaged agentsAgents created or managed outside Agent 365, without its risk protection and observability
Agents without ownersShared agents can become ownerless when their creator is deleted from the organisation
Risk signalsAggregated from Microsoft Entra, Microsoft Defender and Microsoft Purview; needs an E7 or Agent 365 licence
RolesApproving requests and assigning owners is limited to the AI Administrator or Global Administrator roles
Draft agentsLearn says only Copilot Studio drafts are currently visible

Learn also documents Connected platforms, which can sync supported third-party platforms into the registry. Sync is manual, and observability varies by platform. The Agent 365 registry and unmanaged agent discovery skill compares registered agents with unmanaged ones and produces a review list.

How do you find unmanaged and shadow agents?

Shadow AI in the Microsoft 365 admin centre discovers consumer AI apps and standalone agents used without IT approval. It is a public preview in the Frontier programme. Detection depends on Microsoft Defender for Endpoint on devices. Learn lists a Microsoft 365 E5 licence to view shadow agents, Intune enrolment for managed Windows devices, and Global Secure Access for additional usage metadata.

Learn documentsDetail
Detected in previewOpenClaw, ChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw/ZeroClaw, OpenCode and Claude Desktop
BlockingAvailable for OpenClaw only, on Intune-managed Windows devices
Policy timingThe Intune policy can take from 15 minutes up to 8 hours to apply
Traffic fieldsTotal traffic, users, most recent activity and last scanned need Global Secure Access

For generative AI web apps rather than local agents, use Shadow AI app discovery, which reads Defender for Cloud Apps and Purview signals.

Who is accountable for each agent identity?

Microsoft Entra Agent ID gives agents their own identity. Learn says an agent identity can have a sponsor, which records the human user or group accountable for the agent. Learn gives contacting a human when a security incident happens as one use of the sponsor.

Learn documents these governance behaviours:

  • When a sponsor leaves, sponsorship transfers automatically to the sponsor’s manager.
  • Lifecycle Workflows include tasks to email the manager or cosponsors about sponsorship changes, and to transfer sponsorships to the manager. They run only under mover or leaver templates.
  • Agent identities do not hold credentials of their own. They rely on the blueprint to acquire tokens.

The Entra Agent ID audit inventories agent identities and flags orphaned ones. The Entra agent sponsorship lifecycle skill checks that each has an active sponsor, and Conditional Access for agents drafts a policy specification for review.

Which tools and MCP servers can agents use?

The Tools page in the Microsoft 365 admin centre lists plugins, skills, MCP servers and connectors that agents can use. Under Agents, Tools, Registry you can filter by status and publisher and block or unblock a tool. A preview view shows which Power Platform connectors agents use, without management controls.

Learn’s registry article carries a notice that third-party MCP servers are non-Microsoft products used at your own risk, and that data such as authentication keys and prompt content may be passed to them. It recommends vetting servers and monitoring cascading behaviour. The Agent 365 tools and MCP governance baseline inventories what is activated or blocked.

How do Copilot Studio agents fit in?

Copilot Studio governs agents through data policies in the Power Platform admin centre. Learn says these cover knowledge sources, connectors, actions, skills, HTTP requests, channel publication and triggers. Connectors sit in Business, Non-business or Blocked groups, and connectors in different groups cannot share data.

Documented controlDetail from Learn
EnforcementIn effect for all tenants since early 2025; agent exemption is no longer supported
Real timeMakers and users see errors on a data policy violation
Agent 365Onboarded Copilot Studio agents can be represented as Entra identities and governed with Conditional Access
AuditMaker audit logs are visible in Microsoft Purview; Sentinel can alert on agent activity

The Copilot Studio agent inventory lists agents with connectors and sharing scope. The Copilot Studio DLP gap check maps them to the tenant policy, and SharePoint agent publishing audit covers agents published to sites.

What can agents reach through Work IQ?

Work IQ is described by Learn as the intelligence layer that grounds Microsoft 365 Copilot and agents in shared organisational context. In Copilot Studio it is a preview feature. Learn says it is read-only unless an administrator explicitly turns on write operations in the Microsoft 365 admin centre, and admins need a separate spending policy.

Learn also warns that older workload-specific tools (Mail, Teams, OneDrive, SharePoint, Calendar and others) may still appear in the catalogue and are a different experience. The Work IQ API access audit reviews which agents hold access and whether calls are captured in the audit trail.

What is the risk from computer-using agents?

Computer use is a Copilot Studio tool that lets an agent operate websites and desktop apps on a Windows machine by using a virtual mouse and keyboard. Learn documents controls worth checking: access control allow lists, HTTPS enforcement, human supervision and credential choices. Learn does not state audit coverage on that page, so verify it separately.

  • With the default maker-provided credentials, a shared agent lets anyone using it act with the author’s access on the configured machine.
  • Access control stops actions on sites outside the allow list but does not stop the model opening them.
  • Learn recommends dedicated machines, least privilege accounts and application control.

The Computer-Using Agent risk assessment inventories these agents and their approval gates.

What are the prerequisites before you start?

  • An administrator role that can read Agent 365, Entra and Copilot Studio settings. Learn names AI Administrator and Global Administrator for registry actions, and several read roles for Shadow AI.
  • The licensing Learn lists for each feature, such as E7 or Agent 365 for registry risk signals and E5 for Shadow AI.
  • Microsoft Defender for Endpoint on devices for local agent discovery, and Intune enrolment for managed Windows devices.

What should you run first, and why?

Run these read-only skills in order. Each answers one question and feeds the next.

  1. Agent 365 registry and unmanaged agent discovery: build the master list, including agents outside the registry.
  2. Shadow AI app discovery: find unsanctioned generative AI apps that never reach the registry.
  3. Entra Agent ID audit: confirm every agent has an identity and spot orphans.
  4. Entra agent sponsorship lifecycle: confirm a human is accountable for each one.
  5. Conditional Access for agents: specify the access conditions for the riskiest agents.
  6. Workload identity risk audit: review service principals that agents may still rely on.
  7. Agent 365 tools and MCP governance: review the tools those agents can call.
  8. Copilot Studio agent inventory: list makers’ agents, connectors and sharing.
  9. Copilot Studio DLP gap check: test them against data policy.
  10. SharePoint agent publishing audit: check agents published into sites.
  11. Work IQ API access audit: see what organisational context agents can read.
  12. Computer-Using Agent risk: review agents that drive user interfaces.
  13. Copilot Control System governance validator, Autonomous agent governance and Copilot Notebooks governance: review tenant-level settings and adjacent surfaces.
  14. Agent audit trail forensics: reconstruct what an agent did when something goes wrong.

What do these skills prove, and what don’t they?

Skills in this library are read-only by default. They inspect configuration and produce evidence, a report or a remediation plan. They do not certify compliance and they do not change any agent, policy or setting. A clean result shows the tenant matched a documented control on the day it ran.

Read the sibling guides for the wider picture:

Sources


Licensed under CC BY 4.0  by EDUC4TE .

Last reviewed 2026-09-30

Last updated on