Skip to Content
Cowork (Agentic AI)Agent 365 Registry and Unmanaged Agent Discovery

Agent 365 Registry and Unmanaged Agent Discovery (Shadow AI)

TL;DR: This skill compares the agents registered in Microsoft Agent 365 with unmanaged agents found on endpoints, using Microsoft 365 admin centre, Microsoft Defender and Intune signals. It produces an inventory and a review list for administrators. It is read-only and changes nothing.

How is this different from the Agent 365 tools governance baseline?

The Agent 365 Tools and MCP Server Governance Baseline audits which MCP servers the tenant has allowed or blocked. This skill answers a different question: which agents exist at all, which of them sit inside the Agent 365 registry, and which are running on devices without registration. Use the two together, because Defender lists the MCP servers configured on each discovered local agent, and that list is the bridge back to the tenant-level approval decisions.

QuestionTools governance baselineThis skill
Primary objectMCP servers and their toolsAgents (registered and unmanaged)
Main surfaceAgents and Tools in the Microsoft 365 admin centreRegistry, Local agents, Shadow AI, Defender AI agents
Typical triggerA developer requests a BYO MCP serverAn admin asks what AI is actually running here
OutputMCP catalogue and approval backlogRegistered-versus-unmanaged agent inventory and review list

What is the Agent 365 registry and what counts as an unmanaged agent?

Per Microsoft Learn, the agent registry in the Microsoft 365 admin centre is a centralised view of all agents available to your organisation, and it reports Total agents, Agents without owners and Unmanaged agents. Learn defines unmanaged agents as those created or managed outside of Agent 365, without its risk protection and observability. Learn also states that Agent 365 is becoming the unified registry and control plane for agents, with Microsoft Entra continuing to provide the identity foundation through Agent ID.

TermMeaning per Microsoft LearnWhere you see it
RegistryCentralised view of all agents available to the organisationMicrosoft 365 admin centre: Agents > All Agents > Registry
Unmanaged agents (registry card)Agents created or managed outside Agent 365, without its risk protection and observabilityRegistry summary
Local agentsDeveloper-controlled tools such as IDE plugins, CLIs and code editors, intentionally integrated into workflowsLocal Agents (Frontier) page
Shadow AIConsumer-facing AI applications and standalone agents deployed without IT visibility or approvalShadow AI (Frontier) page

When should you run this skill?

  • “Which AI agents are running on our endpoints that IT has not registered?”
  • “Are developers using Claude Code, GitHub Copilot CLI or Cursor on managed devices?”
  • “How many agents in our registry have no owner?”
  • “Which local agents auto-approve their own actions?”
  • “Can we connect AWS or Google Cloud agent platforms into the registry?”
  • “Produce a shadow AI evidence pack before we decide on blocking”

What do you need before you start?

  • Microsoft Agent 365 or Microsoft 365 E7 to view registry risk signals (per Learn)
  • Microsoft Defender for Endpoint Plan 2, with devices onboarded and Microsoft Defender Antivirus in active mode with real-time protection, for local agent discovery
  • Commercial cloud only: Learn states sovereign and national clouds are not supported for local agent discovery
  • Microsoft Intune enrolment for managed Windows devices (Learn lists this as a prerequisite for the Local agents and Shadow AI pages, and states Shadow AI blocking applies only to these devices)
  • Opt-in to the Frontier preview programme for the Local agents and Shadow AI pages
  • Global Secure Access enabled on the tenant and enrolled devices if you want user and traffic metadata on those pages
  • A read-only administrative role from the table in the permissions section below

How this skill works, step by step

  1. Sign in to the Microsoft 365 admin centre and open Agents > All Agents > Registry. Record Total agents, Agents without owners and Unmanaged agents.
  2. Clear all filters (Learn tips that an existing filter is a possible reason expected agents are missing), then export the list to CSV. Record status, publisher type, platform, owner and channel for each agent.
  3. Open Manage on the Connected platforms web part and list each connection with its last run date, latest synchronisation status, synchronised agent count and errors. Learn states manual synchronisation is required after saving a connection, so a stale last run date means agents from that platform may be missing.
  4. Open Agents > Shadow AI and record, for each detected agent, devices, users, first accessed, most recent activity and whether a blocking Intune policy is applied.
  5. Open All Agents > Local Agents (Frontier) and record the same fields for each detected local agent. Open the Detected devices tab for the agents that matter.
  6. Note which fields are blank. Learn states user, activity and traffic fields on these pages populate only when Global Secure Access is enabled.
  7. In the Microsoft Defender portal, open Assets > AI agents > Local agents. Record one row per agent installation with device, account, MCP server counts and first seen.
  8. Run the advanced hunting query below against AgentsInfo to list local agents with vendor, version and device. Filter out records whose lifecycle status is Deleted or Uninstalled.
  9. Query for local agents where autoApprove is "true" or trustedProcess is "false". These act without asking the user, or run in a host process Defender does not trust.
  10. For each discovered agent with configured MCP servers, compare the server names and endpoints with the tenant catalogue from the tools governance baseline.
  11. Open the Risks column in the registry for registered agents. Note the contributing platform (Entra, Defender, Purview) shown in the Risk details pane, and remember counts can lag the security portals by up to an hour.
  12. Cross-check identity and lifecycle using Entra Agent ID Audit and Entra Agent Identity Sponsorship Lifecycle.
  13. Produce the inventory and review list below. Do not click Block agent, Apply Policies or Sync agents while running this skill.
AgentsInfo | where Platform == "LocalAgents" | summarize arg_max(Timestamp, Name, Version, LifecycleStatus, RawAgentInfo) by AgentId | where LifecycleStatus !in~ ("Deleted", "Uninstalled") | extend AgentMetadata = RawAgentInfo.localAgentMetadata | extend AutoApprove = tostring(AgentMetadata.autoApprove), TrustedProcess = tostring(AgentMetadata.trustedProcess), Vendor = tostring(AgentMetadata.vendor), Device = tostring(AgentMetadata.deviceName) | project Name, Vendor, Version, Device, AutoApprove, TrustedProcess

Which Microsoft signals surface unmanaged and local agents?

Each surface answers a different part of the question, and none of them alone gives the full picture.

SignalWhat it showsStatus at 2026-09-30Source of truth for
Registry (Microsoft 365 admin centre)All agents available to the tenant, unmanaged count, ownerless count, risk signalsRegistry documented as a capability within Agent 365; Agent 365 general availability for commercial customers announced 1 May 2026 (Microsoft Security Blog)Registered agents
Connected platforms (registry sync)Agents synchronised from Amazon Bedrock, Google Vertex AI, Salesforce Agentforce, Databricks Genie, Anthropic Claude Managed Agents, Oracle Generative AI Agents and Snowflake CortexLearn page does not state a preview or GA label; the May 2026 blog announced registry sync with AWS Bedrock and Google Cloud connections as public previewThird-party platform agents
Shadow AI (Frontier) pageDetected consumer-style agents such as OpenClaw, ChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw/ZeroClaw, OpenCode and Claude DesktopPublic preview (Frontier)Unapproved standalone agents on managed Windows devices
Local Agents (Frontier) pageDetected developer tools such as Claude Code, Cursor, GitHub Copilot CLI and VS Code extension agentsPublic preview (Frontier)Developer agents on managed Windows devices
Defender AI agents inventoryLocal agents per device, account and MCP server configuration, plus risk where licensedWindows discovery documented without a preview label; macOS discovery is in previewEndpoint ground truth across Windows and macOS
Advanced hunting (AgentsInfo, exposure graph tables)Agent configuration, auto-approve and trust flags, what the agent can reachDocumented; AgentsInfo replaces the earlier AIAgentsInfo tableCustom reporting and evidence
IntuneThe blocking policy created when an admin blocks a detected agentPolicy named A365 - Block OpenClaw; can take 15 minutes to 8 hours to applyEnforcement (out of scope here)

What is the difference between Shadow AI and Local agents?

Per Microsoft Learn, Local agents are intentionally chosen developer tools managed within known environments, while Shadow AI consists of unmanaged, autonomous applications deployed without organisational awareness. In practice, treat a Local agents hit as a governance and configuration question, and a Shadow AI hit as an approval question. Learn lists different detected products on each page, so review both.

Which agents can be detected and blocked today?

Per Microsoft Learn, in the public preview detection is available for every agent listed on the two pages, while blocking is available only for a subset.

PageDetect and blockDetect only
Shadow AI (Frontier)OpenClawChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw/ZeroClaw, OpenCode, Claude Desktop
Local Agents (Frontier)Gemini CLI and the VS Code extensions for Claude Code, Cline, Codex, Gemini Code Assist, GitHub Copilot and Roo CodeClaude Code, Codex CLI, Codex Desktop, Cursor, GitHub Copilot CLI, GitHub Copilot App, Warp, Windsurf, Kiro, Junie CLI, Antigravity, Devin Desktop, Microsoft Scout

Learn also warns that Node.js-based agents (OpenClaw, QClaw, Claw/Nanobot and Gemini CLI) share a single run type, so blocking one blocks them all. This skill only reads; treat that warning as a change-control note before anyone applies a block.

Output format

Registered versus unmanaged agent inventory

The rows below are illustrative placeholders, not real data.

AgentWhere foundRegistered in Agent 365OwnerDevicesUsersMCP serversAuto-approveBlocking availableRisk
Contoso HR AssistantRegistryYesNamedn/an/an/an/an/aLow
Ownerless shared agentRegistryYesNonen/an/an/an/an/aReview
Claude CodeDefender local agentsNon/a14113Yes on 2 devicesNo (Local agents page)High
OpenClawShadow AI pageNon/a22UnknownUnknownYesHigh

Discovery summary

  • Total agents in registry: N | Agents without owners: N | Unmanaged agents (registry card): N
  • Connected platforms: N | Connections with a stale last run date: N | Synchronisation errors: N
  • Shadow AI agents detected: N (devices: N, users: N)
  • Local agents detected: N (devices: N, users: N)
  • Defender local agent installations: N | Auto-approve enabled: N | Host process not trusted: N
  • Discovered agents with MCP servers not in the tenant catalogue: N
  • Fields not populated because Global Secure Access is off: Yes / No
  • Recommended actions: assign owners to ownerless agents; decide allow or block for each detected agent through change control; review every auto-approve agent on a critical device; confirm connected platform synchronisation is current

What does an admin need to review afterwards?

  • Every detected agent with no approved business use: hand to the decision owner, do not block from this skill
  • Auto-approve agents: confirm the account and device the agent runs under, because Learn notes these define what the agent can do unsupervised
  • Local MCP servers: review the start command reported by Defender, since local MCP servers are reported only in AgentsInfo
  • Blank Global Secure Access fields: decide whether the missing user and traffic evidence is acceptable
  • Coverage gaps: devices not onboarded to Defender for Endpoint, and sovereign or national clouds (not supported for local agent discovery), fall outside what Learn documents as detected

Scope and safety

Read-only. This skill does NOT:

  • Click Block agent or Apply Policies, or create the Intune policy that blocking generates
  • Start Sync agents on any connected platform, or create, edit or delete platform connections
  • Upload, block, delete or reassign agents in the registry
  • Change Defender, Entra or Global Secure Access configuration
  • Modify VS Code extension policies

Licensing and permissions

Licences and add-ons

Capability usedMinimum licence per Microsoft Learn
Registry risk signals in the admin centreMicrosoft 365 E7 or Microsoft Agent 365
Local AI agent discovery, inventory and AgentsInfo hunting in DefenderMicrosoft Defender for Endpoint Plan 2 (included in Microsoft 365 E5 and E7)
Risk level, risk indicators and recommendations for discovered local agentsMicrosoft 365 E7, or Microsoft Agent 365 together with Defender for Endpoint Plan 2
Local Agents (Frontier) pageMicrosoft 365 E3 to view, plus Frontier opt-in and Intune enrolment
Shadow AI (Frontier) pageMicrosoft 365 E5 to view, plus Frontier opt-in, Defender for Endpoint and Intune enrolment
User and traffic metadata on those pagesGlobal Secure Access via Microsoft Entra Internet Access, Microsoft Entra Suite or Microsoft 365 E7

Microsoft Learn states different minimum licences on the Local Agents (E3) and Shadow AI (E5) pages. Confirm the current requirement on the live pages before quoting either to a client.

Least-privilege roles

  • Global Reader, Security Reader or Reports Reader to view the Local agents and Shadow AI pages (all are in the role list on those pages)
  • Security Reader or AI Administrator to follow Defender and Entra deep links from registry risk details
  • Learn states the Agent 365 AI administrator creates and manages Connected platforms connections; this skill does not create or change them

Microsoft Graph permissions (read-only)

  • CopilotPackages.Read.All to list registry agents through the Agent Registry packages API, which Learn labels as preview and states works with the AI Administrator role
  • The cited Learn pages document no Graph permission for the Local agents, Shadow AI or Defender inventory pages; they are read through the portals and advanced hunting

Sources


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Last reviewed 2026-09-30

Last updated on