Microsoft Agent 365

Microsoft

Vendor

Control plane to observe, govern and secure an organization's AI agents via a central registry, Entra, Purview and Defender.

Curated by Tiberiu ArvaVerified

Proprietary

Strengths

  • Central agent registry and agent map
  • Entra, Purview and Defender coverage for agents
  • Agent activity in Purview unified audit log

Practitioner note

Strongest fit for Microsoft 365 / E5 tenants that want agent inventory and policy in the same Entra, Purview and Defender stack as users; licensing is per user, so model cost against everyone who owns or uses managed agents.

Warning

Microsoft Agent 365: Generally available for the Commercial segment since 2026-05-01; registry sync with AWS Bedrock and Google Cloud was announced as public preview at GA.

Governance posture

Reviewed 2026-09-30
UnknownData residency

Agent 365 overview and GA post do not state data-residency commitments specific to Agent 365.

YesDeployment model

Microsoft-hosted cloud service managed from the Microsoft 365 admin center; no self-hosted option. (saas)

Source
YesAudit logging

Agent invocations, tool calls, inference calls and guardrail events are recorded in the Microsoft 365 (Purview) audit log.

Source
UnknownSOC 2

No Agent 365-specific SOC 2 scope statement found in the reviewed sources.

UnknownISO 27001

No Agent 365-specific ISO 27001 scope statement found in the reviewed sources.

NoISO 42001

Agent 365 is not in Microsoft's published list of AI services in scope for ISO 42001 (as of review).

Source
N/AEU AI Act

Governance and security tooling for agents, not itself an AI system placed on the market; obligations rest with agent providers and deployers. (role: not-applicable)

YesLicense risk

Proprietary Microsoft SaaS licensed per user; ties agent governance to the Microsoft 365 security stack. (medium)

Source

EU AI Act obligations

Risk tier: Not applicable · as of 2026-08-23

Source-backed information mapped from Microsoft Agent 365's tracked risk tier — not legal advice. Obligations depend on how your organisation deploys the system; see the full obligation reference and timeline.

This record's EU AI Act risk tier is marked not applicable, so no tier-specific obligations attach. Deployers embedding it in an AI system in scope of the Act should assess that system's own tier.

Explore the category

Compare this tool against the rest of its category and the cloud platform foundation layer.