Agentshield

Microsoft Agent 365 Security: Pricing, Licensing and Agent Governance Controls

Agent 365 is the most complete agent control plane any platform vendor ships, and most Microsoft-stack teams should buy it. The gap worth understanding before you sign is narrow: coverage depends on which runtime an agent was built in, and the blocking rules are threat-shaped rather than policy-shaped.

OWASP LLM Top 10 Immutable audit trail Never trains on your data

Direct answer

Microsoft Agent 365 became generally available on 1 May 2026 and gives every registered agent an Entra identity, a place in the Microsoft 365 admin center registry, Purview data controls and Defender threat detection. It lists at 15 US dollars per user per month on an annual commitment, or arrives inside Microsoft 365 E7 at 99 dollars per user per month, and it is licensed per user rather than per agent. Three documented boundaries decide whether it is enough on its own. Defender real-time protection evaluates tool invocations through Work IQ MCP, and Microsoft states that agents relying on unsupported tools or not integrating with Work IQ MCP are not covered. The built-in rule audits without stopping anything, so blocking only happens for custom rules you write against four threat categories. And agents built outside Copilot Studio, Microsoft Foundry and the Microsoft 365 Copilot Agent Builder emit no observability at all until a developer wires in the Agent 365 SDK.

Try it live

Watch Agentshield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
Interactive demo · 0 blocked in this session

Run a request

Runs the live engine on your text. Nothing is stored, no account needed.

Inspection lane

INSPECTING
untrusted input

Policy trace

High-risk action held for approval

Audit trail

The risk

The registry fills up faster than the coverage does. An admin opens the Agent 365 overview, sees a clean inventory with owners and sponsors attached, and reasonably concludes the estate is governed. What the inventory does not show is which of those agents Defender can actually inspect at runtime, which ones only appear because someone registered them by hand, and which ones are visible but unprotected. A Bedrock agent surfaced in the admin center looks identical in a screenshot to a Copilot Studio agent covered by a blocking rule. The difference only becomes visible during an incident, which is the worst possible time to discover it.

How Agentshield handles it

Buy Agent 365 if you run agents in the Microsoft stack, because nothing you add replaces the identity, data and posture layers it gives you, and most of them have no third-party equivalent. Then do three things the platform does not do for you. Turn the default audit rule into real custom blocking rules scoped to the agents that can take irreversible actions, because auditing is the shipped default and it stops nothing. Get an accurate picture of coverage rather than inventory: list every agent by runtime, and mark which ones emit Agent 365 observability natively, which ones were wired in through the SDK, and which ones are visible but silent. Then put a deterministic policy gate in front of the tool calls that matter, so a refund above a threshold, a production write or an outbound email is checked against a rule you wrote and approved by a named human, with one audit record that covers your Microsoft, AWS and Google agents rather than three separate consoles.

The controls

The controls that secure the agents you register in Microsoft Agent 365, and the actions those agents take once they leave the Microsoft graph.

Is Microsoft Agent 365 secure? What Microsoft covers in 2026

Yes, and more thoroughly than any other platform vendor currently manages. It is worth being precise about which parts, because the writing on this product is either a launch recap or a licensing spreadsheet, and neither tells a security owner what is actually enforced. Everything below is taken from Microsoft Learn rather than from a keynote.

Agent 365 organizes itself around three pillars Microsoft names directly: observe, govern and secure. The security half runs through products you probably already own.

ControlWhat Microsoft documentsWhere it sits
Agent registry and agent mapA single centralized registry giving a unified view of agent adoption, activity and health, with role-specific oversight so security and business leaders see the slice relevant to themInventory
Entra Agent IDVisibility into all agent identities, including agents with an Entra Agent ID, agents you register yourself, and shadow agents. Conditional Access and identity protection policies extend from users to agents, with real-time access decisions based on agent context, risk level and resource sensitivityIdentity and access
Secure Access Service Edge for agentsMonitors and blocks malicious and non-compliant network traffic from agents running on user devices, including Copilot Studio agentsNetwork egress
Purview data controlsData security posture management for agent interactions, sensitivity label inheritance, DLP that blocks agents from accessing and sharing sensitive content, insider risk management, auditing of agent interactions, retention and deletion policies, and eDiscovery over agent outputsData
Defender agent posture managementIdentifies and remediates agent misconfigurations and exposure risks, and visualizes attack paths from agents to critical assetsPosture
Defender detection and real-time protectionDetects jailbreak attempts, indirect prompt injection, malicious content propagation, secret and credential leakage, evasion techniques, LLM reconnaissance and suspicious user or IP access, and can block matching actions before they executeRuntime
Advanced Hunting over agent activityAgent 365 observability data lands in queryable tables including CloudAppEvents, AgentsInfo and BehaviorInfo, so agent tool invocations can be traced with KQL alongside identity and device dataInvestigation

That is a serious stack and it deserves to be said plainly: a team that buys Agent 365 and turns all of this on is further ahead than the large majority of agent deployments we look at. Several of these layers have no meaningful third-party equivalent. Nobody else can give an agent a first-class identity in your directory and then apply the same Conditional Access policy engine your humans already sit behind. If a vendor tells you Agent 365 is a dashboard, they have not read the documentation.

Microsoft also names the problems it is solving, which is more candid than the category norm: agent sprawl from user-created and SaaS agents, over-privileged agents with excessive resource access, tool misuse when agents are manipulated into abusing authorized tools, misconfigured agents without proper authentication or boundaries, and traditional AI threats such as prompt injection and data leakage now extending across agent interactions. That list is accurate. The rest of this page is about where the shipped controls land against it, and it is built on Microsoft's own published limits rather than on speculation.

Microsoft Agent 365 pricing and licensing: what the per-user license covers

Pricing shapes the security decision here more than it usually does, because the licensing unit is unusual and it changes who is covered. Figures below are Microsoft list prices read from the Agent 365 product page in September 2026. Prices change and regional and negotiated pricing differ, so treat these as the starting point for a quote rather than as your quote.

OptionList priceCommitmentWhat it means for coverage
Agent 365 standalone15 USD per user per monthPaid yearly, annual commitmentThe control plane on its own. Existing Microsoft cloud subscribers can sign in and start
Microsoft 365 E799 USD per user per monthPaid yearlyAgent 365 arrives inside the suite alongside the productivity, security and identity components
Microsoft 365 E7 (No Teams)90.45 USD per user per monthPaid yearlyThe same bundle for tenants that license Teams separately
PrerequisiteMicrosoft E5 recommendedn/aMicrosoft states Agent 365 works best when using Microsoft E5 as a prerequisite, and that at least one user must hold a qualifying Agent 365 license to enable it

The unit is the part that surprises people. Agent 365 is licensed per user, not per agent, and Microsoft recommends the license for every user who interacts with, owns, manages or sponsors an agent that Agent 365 manages. Read that carefully, because it cuts both ways depending on your shape.

If you are a 40 person company running 300 automated agents, this is the cheapest agent governance any vendor offers, because deploying the three hundred and first agent adds nothing to the bill. If you are a 6,000 person enterprise where most staff will eventually chat with an agent in Teams, the recommended coverage is a six figure annual line item, and the number of agents you actually run has no bearing on it. Neither outcome is a criticism of the model. It just means the security question and the budget question have to be answered together, and the person doing your threat model should see the license count before it is signed.

One more detail worth putting in front of finance: there is no consumption charge for Agent 365 itself today, but the platforms the agents are built on bill separately. Copilot Studio and Microsoft Foundry carry their own consumption meters, and Microsoft 365 Copilot is a separate per-user license again. We walk through the two Copilot products people most often confuse in Microsoft 365 Copilot vs Security Copilot pricing, and the data-exposure side of the assistant itself in Microsoft 365 Copilot security.

What Agent 365 real-time protection blocks, and what it does not

This is the section that matters if you are deciding whether Agent 365 alone closes your agent risk, because it is the only layer that stops an action rather than recording it. Microsoft documents both the mechanism and its edges clearly.

Real-time protection inspects agent activity throughout the agentic loop and blocks risky actions before they execute. Coverage depends on the agent type, and Microsoft states the boundary in one sentence worth quoting: "Agents that rely on unsupported tools or don't integrate with Work IQ MCP aren't covered." Protection for Copilot Studio agents and for Foundry agents are both marked Preview in the same documentation.

BoundaryWhat Microsoft documentsWhy it matters to a buyer
The default rule does not blockA built-in Default rule audits all agents, recording matching activity as a behavior without stopping the action. Custom rules block matching actions before they executeOut of the box, nothing is prevented. Blocking exists only for rules a person deliberately writes and scopes, which is a reasonable rollout design and a common reason a tenant is quieter than its owner assumes
Four detection types, not policiesCustom blocking rules are built from detection types: secret exfiltration, malicious content propagation, evasion techniques and unsafe email domainThese are threat categories, not business rules. There is no detection type for "this agent may never issue a refund above 500 dollars" or "any production write needs a named approver", because that is not what the mechanism is for
Blocking suppresses alertingNear-real-time detections continue to surface as alerts only in audit mode. When a blocking rule covers an agent, near-real-time alerts are not generated for that agentAn operational trade rather than a flaw, but it needs to be known before you scope rules. Your most protected agents become your least alerted agents
Detection is in public previewThe Defender AI agent detection and investigation documentation carries a public preview notice and the Microsoft Defender preview termsPreview features can change and are not covered by GA support commitments. The control plane is generally available; several of the security capabilities inside it are not yet
Local agents onboard separatelyLocal AI agents running on endpoints are covered through Defender for Endpoint runtime protection, are onboarded separately from cloud agents, and require Defender for Endpoint in active modeDeveloper laptops running coding agents are a different project with a different prerequisite, not a checkbox in the same console
Prompt evidence is on by defaultPrompt snippets exchanged between user and agent are included as evidence in each alert by default. Sensitive data and secrets are redacted, and Microsoft notes customer conversations might still be sensitive in natureWorth a deliberate decision rather than a default, particularly in regulated or privileged-communication contexts

None of this is a knock on Microsoft. Publishing the Work IQ MCP coverage boundary in the same article as the feature is more honest than most of this category manages, and a threat-detection engine that catches indirect prompt injection is genuinely valuable. The distinction to hold on to is between detection, which asks whether an action looks malicious, and authorization, which asks whether this agent was ever permitted to take this action at all. Detection is probabilistic and improves over time. Authorization is deterministic and you can hand it to an auditor. The vendor-neutral version of that argument sits on AI agent guardrails, and the injection problem specifically on prompt injection protection.

Which agents Agent 365 can actually see: the SDK boundary

Inventory and coverage are two different numbers, and the registry only shows you the first one. Microsoft is explicit about which runtimes emit the observability data every downstream control depends on.

Where the agent was builtObservability statusWork required
Copilot StudioSends observability data to Microsoft 365 by defaultNone, beyond connecting Copilot Studio for real-time protection
Microsoft FoundrySends observability data by default, but Microsoft states threat detection is supported only for published Foundry agents. Unpublished agents, including agents used only in a playground environment, are not supportedPublish the agent. A pilot running in a playground is outside detection
Microsoft 365 Copilot Agent BuilderDeclarative agents send observability data by defaultNone
Any other platform, including LangChain, custom Python services and in-house agentsNo observability until it is wired inA developer integrates the Microsoft Agent 365 SDK. This is engineering work on your side, per agent
Google Vertex AI and Amazon Bedrock agentsCan be made visible in the Microsoft 365 admin center automatically, with no development workRegistration only. Visibility is not the same as runtime evaluation
Partner agent factories such as Kore, Kasisto, n8n and NVIDIA NeMoAgents built on these platforms are currently deployed as AI teammates, and Microsoft states AI teammate is available to Frontier program participants onlyFrontier program participation. Several partner integrations, including Adobe, Celonis, Egnyte, Manus and NVIDIA, were listed as coming soon as of August 2026

The practical consequence is a coverage map that does not match the org chart. The agents built by your platform team in Copilot Studio are the best protected things in the estate. The agent a data scientist shipped in Python nine months ago, the one holding a service principal with write access to a production system, is the one that needs the SDK integration nobody has scheduled. Sprawl is not the hard part here. Microsoft solved discovery, including shadow agents. The hard part is that the least governed agents are also the ones that cost the most engineering effort to bring under governance.

One more asymmetry is worth naming while you plan. Block events from Microsoft Prompt Shields for Foundry and the Microsoft 365 Copilot Agent Builder are recorded as behaviors, and Microsoft notes this is not yet supported for agents built with Copilot Studio. Two agents built by two teams in two Microsoft products produce different evidence for the same event. If you are assembling one control narrative for an auditor, that difference is the sort of thing you want to find now rather than during fieldwork. The same evidence problem across a mixed estate is what an immutable audit trail is for.

Microsoft Agent 365 alternatives compared: what to buy and what you already have

Comparison tables in this category are usually written so the vendor wins every row, which is worthless to the person signing the purchase order. This one marks the rows where Microsoft is the right answer and we are not. Five of eight go to Microsoft, and that is not a rhetorical device, it is what the documentation supports.

What you needBest answerWhy
An inventory of every agent, including shadow agentsAgent 365Discovery across Entra, the admin center and self-registered agents, with sponsors and ownership attached. Buy nothing else for this
Agent identity with Conditional AccessAgent 365 and Entra Agent IDNobody outside Microsoft can put an agent behind the same policy engine as your workforce. There is no third-party substitute
Sensitivity labels, DLP and eDiscovery over agent dataPurview, inside Agent 365If your data classification already lives in Purview, extending it to agents is a configuration change rather than a purchase
Posture management and attack path analysisDefender, inside Agent 365Misconfiguration and exposure analysis that reads the rest of your Microsoft estate. Third-party posture tools see less
Threat detection on agent behavior in a Microsoft-only estateDefender, inside Agent 365Jailbreak, indirect prompt injection and credential leakage detection correlated into incidents your SOC already works. Note the preview status and plan accordingly
Deterministic per-tool authorization and approval gates on irreversible actionsAgentshieldDetection types are threat categories. A rule that says this agent may call this tool, up to this value, and anything above it waits for a named human is a different mechanism, and it is the one that survives an audit question about intent
Uniform control over agents outside the Microsoft runtimesAgentshieldBedrock and Vertex agents can be made visible in the admin center, and everything else needs the Agent 365 SDK integrated per agent. A gateway in front of the tool call does not care which framework produced it
One audit record across Microsoft, AWS and Google agentsAgentshieldThree clouds, three consoles, three evidence formats. If your regulator asks what every agent did last quarter, the answer should not require reconciling three exports by hand

The honest summary is that Agent 365 and a runtime policy layer are not competitors in most tenants. Agent 365 answers who the agent is, what data it may reach and whether its behavior looks malicious. A policy gate answers whether the specific action it just proposed is allowed and who approved it. Teams that are entirely inside the Microsoft stack, running Copilot Studio agents, with no irreversible actions in play, genuinely do not need a second product yet. Teams running agents across more than one cloud, or agents that move money, send external mail or write to production, are buying two different things and should stop trying to make one of them do the other job.

The same reasoning applies on the other platforms and we have written it out for each: Microsoft Foundry agent security, Bedrock AgentCore security, Gemini Enterprise security and Snowflake Cortex agent security. Every one of those platforms governs which data an agent may reach. None of them decides whether the action it just proposed should happen.

How to secure agents in an Agent 365 tenant: the order of work

Six steps, in the order that removes the most risk per hour of effort. Nothing here needs a purchase before step six.

1. Enable the Microsoft 365 app connector and turn on security for AI agents. Nothing in Defender works for agents until Agent 365 observability data is flowing. This is the prerequisite Microsoft lists first and the one most commonly half-finished, usually because the person who bought the license and the person who owns the Defender tenant are different people.

2. Build the coverage map, not the inventory. Export the registry, then add a column nobody gets from the console: how each agent emits observability. Native from Copilot Studio, native from a published Foundry agent, SDK-integrated, registered-but-silent, or unknown. The unknown rows are your actual project. Expect the list to be shorter and more alarming than the inventory count suggests.

3. Give every agent a sponsor and a scoped identity. Entra Agent ID with Conditional Access is the highest-value control in the whole product and it is included. Scope each agent to the resources it needs rather than to the permissions the pilot happened to have. Ownership that expires matters as much as ownership that exists, which is why Microsoft ships agent lifecycle governance alongside the identity. The general version of this is on AI agent identity and access management.

4. Convert the default audit rule into real blocking rules. The shipped rule records and stops nothing. Pick the agents that can take an irreversible action, write custom rules against the detection types that apply, and accept the documented trade that blocked agents stop generating near-real-time alerts. Do this before a pilot becomes production, because the rule that would have caught the incident is rarely written afterwards in time.

5. Decide the prompt evidence question deliberately. Prompt snippets are attached to alerts by default with secrets redacted. In a legal, clinical or HR context that default deserves a documented decision rather than an inherited setting.

6. Put a deterministic gate in front of the actions that cannot be undone. This is the part no platform control does, on any cloud. A rule you wrote, evaluated before the tool call executes, with a human approval on the cases that warrant one and a single record of the decision. If every agent you run lives in Copilot Studio and none of them can move money, skip this step and revisit it when that stops being true. If you run agents in three clouds, this is the layer that makes them answerable as one estate. Our tool permission controls and human approval gates cover the mechanism in detail.

FAQ

Common questions about microsoft agent 365 security.

What is Microsoft Agent 365?

It is Microsoft's control plane for AI agents, generally available since 1 May 2026. It provides a centralized registry of every agent in the tenant, gives agents identities in Microsoft Entra, extends Purview data controls and Defender threat protection to agent activity, and organizes all of it around three pillars Microsoft names as observe, govern and secure.

How much does Microsoft Agent 365 cost?

Microsoft lists Agent 365 at 15 US dollars per user per month, paid yearly with an annual commitment. It is also included in Microsoft 365 E7 at 99 dollars per user per month, or 90.45 dollars for the E7 No Teams variant. These are list prices read in September 2026 and your negotiated pricing will differ.

Is Microsoft Agent 365 licensed per user or per agent?

Per user. Microsoft recommends the license for every user who interacts with, owns, manages or sponsors an agent that Agent 365 manages, and deploying more agents does not increase the bill. That makes it inexpensive for a small team running many agents and expensive for a large workforce where most people will eventually talk to one.

What license do you need for Microsoft Agent 365?

Microsoft states Agent 365 works best with Microsoft E5 as a prerequisite, and that at least one user must hold a qualifying Agent 365 license to enable the service in the tenant. Existing Microsoft cloud subscribers can sign in and start from there, which is why the practical prerequisite question is usually about E5 coverage rather than about Agent 365 itself.

Does Microsoft Agent 365 block prompt injection?

Defender detects indirect prompt injection attempts as part of Agent 365 security, and real-time protection rules can block matching actions before they execute. Two caveats belong with that. The detection documentation carries a public preview notice, and the built-in rule audits without blocking, so prevention only happens for custom rules you deliberately create and scope.

What does Agent 365 real-time protection not cover?

Microsoft states it directly: agents that rely on unsupported tools or do not integrate with Work IQ MCP are not covered. Protection for Copilot Studio and Foundry agents is marked Preview, local agents on endpoints are onboarded separately through Defender for Endpoint in active mode, and threat detection for Foundry applies only to published agents, not playground ones.

Can Agent 365 manage agents that are not built on Microsoft?

Partly. Google Vertex AI and Amazon Bedrock agents can be made visible in the Microsoft 365 admin center with no development work, and partner agents and agent factories integrate through the Agent 365 SDK. For anything you built yourself on another framework, a developer has to integrate the SDK before the agent emits any observability data at all, so visibility on non-Microsoft agents is a project rather than a setting.

What are the best Microsoft Agent 365 alternatives?

For inventory, agent identity, Purview data controls and Defender posture management there is no real alternative worth buying if you are on Microsoft, because those layers read the rest of your estate. The genuine gap is elsewhere: deterministic per-tool authorization, human approval on irreversible actions, and one audit record across agents running on more than one cloud.

Do I need third-party security tooling with Microsoft Agent 365?

Usually not if every agent lives in Copilot Studio, none of them takes irreversible actions, and your compliance evidence can come from the same vendor being audited. It starts earning its place when agents run in more than one cloud, when an agent can move money or write to production, or when an auditor asks who approved a specific action rather than whether it looked malicious.

Is Microsoft Agent 365 generally available?

The control plane is. Microsoft made Agent 365 generally available for the Commercial segment on 1 May 2026. Several of the security capabilities inside it are not GA yet: the Defender AI agent detection and investigation documentation carries a public preview notice, real-time protection for Copilot Studio and Foundry agents is marked Preview, and Entra agent identity governance is documented as Preview.

How do I audit what an Agent 365 agent did?

Purview logs and audits agent interactions for compliance review, and Defender Advanced Hunting exposes Agent 365 observability data through KQL tables including CloudAppEvents for tool invocations, AgentsInfo for agent configuration and BehaviorInfo for audit and block events. The limit to plan around is that this evidence only exists for agents that actually emit observability data.

Secure your microsoft agent 365 security.