Agent 365 Registry and Unmanaged Agent Discovery (Shadow AI)
TL;DR: This skill compares the agents registered in Microsoft Agent 365 with unmanaged agents found on endpoints, using Microsoft 365 admin centre, Microsoft Defender and Intune signals. It produces an inventory and a review list for administrators. It is read-only and changes nothing.
How is this different from the Agent 365 tools governance baseline?
The Agent 365 Tools and MCP Server Governance Baseline audits which MCP servers the tenant has allowed or blocked. This skill answers a different question: which agents exist at all, which of them sit inside the Agent 365 registry, and which are running on devices without registration. Use the two together, because Defender lists the MCP servers configured on each discovered local agent, and that list is the bridge back to the tenant-level approval decisions.
| Question | Tools governance baseline | This skill |
|---|---|---|
| Primary object | MCP servers and their tools | Agents (registered and unmanaged) |
| Main surface | Agents and Tools in the Microsoft 365 admin centre | Registry, Local agents, Shadow AI, Defender AI agents |
| Typical trigger | A developer requests a BYO MCP server | An admin asks what AI is actually running here |
| Output | MCP catalogue and approval backlog | Registered-versus-unmanaged agent inventory and review list |
What is the Agent 365 registry and what counts as an unmanaged agent?
Per Microsoft Learn, the agent registry in the Microsoft 365 admin centre is a centralised view of all agents available to your organisation, and it reports Total agents, Agents without owners and Unmanaged agents. Learn defines unmanaged agents as those created or managed outside of Agent 365, without its risk protection and observability. Learn also states that Agent 365 is becoming the unified registry and control plane for agents, with Microsoft Entra continuing to provide the identity foundation through Agent ID.
| Term | Meaning per Microsoft Learn | Where you see it |
|---|---|---|
| Registry | Centralised view of all agents available to the organisation | Microsoft 365 admin centre: Agents > All Agents > Registry |
| Unmanaged agents (registry card) | Agents created or managed outside Agent 365, without its risk protection and observability | Registry summary |
| Local agents | Developer-controlled tools such as IDE plugins, CLIs and code editors, intentionally integrated into workflows | Local Agents (Frontier) page |
| Shadow AI | Consumer-facing AI applications and standalone agents deployed without IT visibility or approval | Shadow AI (Frontier) page |
When should you run this skill?
- “Which AI agents are running on our endpoints that IT has not registered?”
- “Are developers using Claude Code, GitHub Copilot CLI or Cursor on managed devices?”
- “How many agents in our registry have no owner?”
- “Which local agents auto-approve their own actions?”
- “Can we connect AWS or Google Cloud agent platforms into the registry?”
- “Produce a shadow AI evidence pack before we decide on blocking”
What do you need before you start?
- Microsoft Agent 365 or Microsoft 365 E7 to view registry risk signals (per Learn)
- Microsoft Defender for Endpoint Plan 2, with devices onboarded and Microsoft Defender Antivirus in active mode with real-time protection, for local agent discovery
- Commercial cloud only: Learn states sovereign and national clouds are not supported for local agent discovery
- Microsoft Intune enrolment for managed Windows devices (Learn lists this as a prerequisite for the Local agents and Shadow AI pages, and states Shadow AI blocking applies only to these devices)
- Opt-in to the Frontier preview programme for the Local agents and Shadow AI pages
- Global Secure Access enabled on the tenant and enrolled devices if you want user and traffic metadata on those pages
- A read-only administrative role from the table in the permissions section below
How this skill works, step by step
- Sign in to the Microsoft 365 admin centre and open Agents > All Agents > Registry. Record Total agents, Agents without owners and Unmanaged agents.
- Clear all filters (Learn tips that an existing filter is a possible reason expected agents are missing), then export the list to CSV. Record status, publisher type, platform, owner and channel for each agent.
- Open Manage on the Connected platforms web part and list each connection with its last run date, latest synchronisation status, synchronised agent count and errors. Learn states manual synchronisation is required after saving a connection, so a stale last run date means agents from that platform may be missing.
- Open Agents > Shadow AI and record, for each detected agent, devices, users, first accessed, most recent activity and whether a blocking Intune policy is applied.
- Open All Agents > Local Agents (Frontier) and record the same fields for each detected local agent. Open the Detected devices tab for the agents that matter.
- Note which fields are blank. Learn states user, activity and traffic fields on these pages populate only when Global Secure Access is enabled.
- In the Microsoft Defender portal, open Assets > AI agents > Local agents. Record one row per agent installation with device, account, MCP server counts and first seen.
- Run the advanced hunting query below against
AgentsInfoto list local agents with vendor, version and device. Filter out records whose lifecycle status isDeletedorUninstalled. - Query for local agents where
autoApproveis"true"ortrustedProcessis"false". These act without asking the user, or run in a host process Defender does not trust. - For each discovered agent with configured MCP servers, compare the server names and endpoints with the tenant catalogue from the tools governance baseline.
- Open the Risks column in the registry for registered agents. Note the contributing platform (Entra, Defender, Purview) shown in the Risk details pane, and remember counts can lag the security portals by up to an hour.
- Cross-check identity and lifecycle using Entra Agent ID Audit and Entra Agent Identity Sponsorship Lifecycle.
- Produce the inventory and review list below. Do not click Block agent, Apply Policies or Sync agents while running this skill.
AgentsInfo
| where Platform == "LocalAgents"
| summarize arg_max(Timestamp, Name, Version, LifecycleStatus, RawAgentInfo) by AgentId
| where LifecycleStatus !in~ ("Deleted", "Uninstalled")
| extend AgentMetadata = RawAgentInfo.localAgentMetadata
| extend AutoApprove = tostring(AgentMetadata.autoApprove),
TrustedProcess = tostring(AgentMetadata.trustedProcess),
Vendor = tostring(AgentMetadata.vendor),
Device = tostring(AgentMetadata.deviceName)
| project Name, Vendor, Version, Device, AutoApprove, TrustedProcessWhich Microsoft signals surface unmanaged and local agents?
Each surface answers a different part of the question, and none of them alone gives the full picture.
| Signal | What it shows | Status at 2026-09-30 | Source of truth for |
|---|---|---|---|
| Registry (Microsoft 365 admin centre) | All agents available to the tenant, unmanaged count, ownerless count, risk signals | Registry documented as a capability within Agent 365; Agent 365 general availability for commercial customers announced 1 May 2026 (Microsoft Security Blog) | Registered agents |
| Connected platforms (registry sync) | Agents synchronised from Amazon Bedrock, Google Vertex AI, Salesforce Agentforce, Databricks Genie, Anthropic Claude Managed Agents, Oracle Generative AI Agents and Snowflake Cortex | Learn page does not state a preview or GA label; the May 2026 blog announced registry sync with AWS Bedrock and Google Cloud connections as public preview | Third-party platform agents |
| Shadow AI (Frontier) page | Detected consumer-style agents such as OpenClaw, ChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw/ZeroClaw, OpenCode and Claude Desktop | Public preview (Frontier) | Unapproved standalone agents on managed Windows devices |
| Local Agents (Frontier) page | Detected developer tools such as Claude Code, Cursor, GitHub Copilot CLI and VS Code extension agents | Public preview (Frontier) | Developer agents on managed Windows devices |
| Defender AI agents inventory | Local agents per device, account and MCP server configuration, plus risk where licensed | Windows discovery documented without a preview label; macOS discovery is in preview | Endpoint ground truth across Windows and macOS |
Advanced hunting (AgentsInfo, exposure graph tables) | Agent configuration, auto-approve and trust flags, what the agent can reach | Documented; AgentsInfo replaces the earlier AIAgentsInfo table | Custom reporting and evidence |
| Intune | The blocking policy created when an admin blocks a detected agent | Policy named A365 - Block OpenClaw; can take 15 minutes to 8 hours to apply | Enforcement (out of scope here) |
What is the difference between Shadow AI and Local agents?
Per Microsoft Learn, Local agents are intentionally chosen developer tools managed within known environments, while Shadow AI consists of unmanaged, autonomous applications deployed without organisational awareness. In practice, treat a Local agents hit as a governance and configuration question, and a Shadow AI hit as an approval question. Learn lists different detected products on each page, so review both.
Which agents can be detected and blocked today?
Per Microsoft Learn, in the public preview detection is available for every agent listed on the two pages, while blocking is available only for a subset.
| Page | Detect and block | Detect only |
|---|---|---|
| Shadow AI (Frontier) | OpenClaw | ChatGPT Desktop, Ollama Desktop, Poe Desktop, Claw/ZeroClaw, OpenCode, Claude Desktop |
| Local Agents (Frontier) | Gemini CLI and the VS Code extensions for Claude Code, Cline, Codex, Gemini Code Assist, GitHub Copilot and Roo Code | Claude Code, Codex CLI, Codex Desktop, Cursor, GitHub Copilot CLI, GitHub Copilot App, Warp, Windsurf, Kiro, Junie CLI, Antigravity, Devin Desktop, Microsoft Scout |
Learn also warns that Node.js-based agents (OpenClaw, QClaw, Claw/Nanobot and Gemini CLI) share a single run type, so blocking one blocks them all. This skill only reads; treat that warning as a change-control note before anyone applies a block.
Output format
Registered versus unmanaged agent inventory
The rows below are illustrative placeholders, not real data.
| Agent | Where found | Registered in Agent 365 | Owner | Devices | Users | MCP servers | Auto-approve | Blocking available | Risk |
|---|---|---|---|---|---|---|---|---|---|
| Contoso HR Assistant | Registry | Yes | Named | n/a | n/a | n/a | n/a | n/a | Low |
| Ownerless shared agent | Registry | Yes | None | n/a | n/a | n/a | n/a | n/a | Review |
| Claude Code | Defender local agents | No | n/a | 14 | 11 | 3 | Yes on 2 devices | No (Local agents page) | High |
| OpenClaw | Shadow AI page | No | n/a | 2 | 2 | Unknown | Unknown | Yes | High |
Discovery summary
- Total agents in registry: N | Agents without owners: N | Unmanaged agents (registry card): N
- Connected platforms: N | Connections with a stale last run date: N | Synchronisation errors: N
- Shadow AI agents detected: N (devices: N, users: N)
- Local agents detected: N (devices: N, users: N)
- Defender local agent installations: N | Auto-approve enabled: N | Host process not trusted: N
- Discovered agents with MCP servers not in the tenant catalogue: N
- Fields not populated because Global Secure Access is off: Yes / No
- Recommended actions: assign owners to ownerless agents; decide allow or block for each detected agent through change control; review every auto-approve agent on a critical device; confirm connected platform synchronisation is current
What does an admin need to review afterwards?
- Every detected agent with no approved business use: hand to the decision owner, do not block from this skill
- Auto-approve agents: confirm the account and device the agent runs under, because Learn notes these define what the agent can do unsupervised
- Local MCP servers: review the start command reported by Defender, since local MCP servers are reported only in
AgentsInfo - Blank Global Secure Access fields: decide whether the missing user and traffic evidence is acceptable
- Coverage gaps: devices not onboarded to Defender for Endpoint, and sovereign or national clouds (not supported for local agent discovery), fall outside what Learn documents as detected
Scope and safety
Read-only. This skill does NOT:
- Click Block agent or Apply Policies, or create the Intune policy that blocking generates
- Start Sync agents on any connected platform, or create, edit or delete platform connections
- Upload, block, delete or reassign agents in the registry
- Change Defender, Entra or Global Secure Access configuration
- Modify VS Code extension policies
Licensing and permissions
Licences and add-ons
| Capability used | Minimum licence per Microsoft Learn |
|---|---|
| Registry risk signals in the admin centre | Microsoft 365 E7 or Microsoft Agent 365 |
Local AI agent discovery, inventory and AgentsInfo hunting in Defender | Microsoft Defender for Endpoint Plan 2 (included in Microsoft 365 E5 and E7) |
| Risk level, risk indicators and recommendations for discovered local agents | Microsoft 365 E7, or Microsoft Agent 365 together with Defender for Endpoint Plan 2 |
| Local Agents (Frontier) page | Microsoft 365 E3 to view, plus Frontier opt-in and Intune enrolment |
| Shadow AI (Frontier) page | Microsoft 365 E5 to view, plus Frontier opt-in, Defender for Endpoint and Intune enrolment |
| User and traffic metadata on those pages | Global Secure Access via Microsoft Entra Internet Access, Microsoft Entra Suite or Microsoft 365 E7 |
Microsoft Learn states different minimum licences on the Local Agents (E3) and Shadow AI (E5) pages. Confirm the current requirement on the live pages before quoting either to a client.
Least-privilege roles
- Global Reader, Security Reader or Reports Reader to view the Local agents and Shadow AI pages (all are in the role list on those pages)
- Security Reader or AI Administrator to follow Defender and Entra deep links from registry risk details
- Learn states the Agent 365 AI administrator creates and manages Connected platforms connections; this skill does not create or change them
Microsoft Graph permissions (read-only)
CopilotPackages.Read.Allto list registry agents through the Agent Registry packages API, which Learn labels as preview and states works with the AI Administrator role- The cited Learn pages document no Graph permission for the Local agents, Shadow AI or Defender inventory pages; they are read through the portals and advanced hunting
Related skills
- Governing AI Agents in Microsoft 365: Start here for the agent governance sequence this discovery feeds.
- Shadow AI App Discovery: Run alongside, for unsanctioned generative AI apps seen in Defender for Cloud Apps.
- Copilot Studio Agent Inventory and Connector Audit: Run after, to inventory Copilot Studio agents with their connectors and DLP coverage.
- Agent 365 Tools and MCP Server Governance Baseline: Run after, to audit available and blocked MCP servers in the Agent 365 tools catalogue.
- Entra Agent ID Audit: Run after, to list agent identities and flag agents with no accountable sponsor.
Sources
- Manage agent registry in Microsoft 365 admin center (Microsoft Learn)
- Connected platforms in Microsoft Agent 365 (Microsoft Learn)
- Local agents in Microsoft 365 admin center, Preview (Microsoft Learn)
- Shadow AI in Microsoft 365 admin center, Preview (Microsoft Learn)
- Local AI agent discovery with Microsoft Defender for Endpoint (Microsoft Learn)
- Discover local AI agents with Microsoft Defender for Endpoint (Microsoft Learn)
- Discover AI agents and assess security posture using Microsoft Defender (Microsoft Learn)
- Agent management in Microsoft 365 admin center (Microsoft Learn)
- Agent Registry convergence with Microsoft Agent 365 (Microsoft Learn)
- Microsoft Agent 365 now generally available (Microsoft Security Blog, 1 May 2026): dated announcement only, used for the GA date and the registry sync announcement
- Preview and GA status is stated as at 30 September 2026 and taken from the Learn pages above; recheck before relying on it
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30