Every licensed user in a default Microsoft 365 tenant can already build and share an agent. That single fact is why 2026 has become the year of agent sprawl. We have seen this pattern before, with Teams sprawl and then Power Platform, where Microsoft made it easy for everyone to spin something up and governance had to catch up afterwards. Agents are the same story moving faster. In the last twelve to eighteen months, suddenly everyone is building them, and the hard questions follow close behind: who created this agent, what does it have access to, and who is going to clean it up.
Gartner puts numbers on the worry. Around 70% of organisations are concerned about agent sprawl, and almost 90% say extra controls are required to manage Copilot agents. At the same time everyone is pushing for AI, so adoption keeps climbing. The share of organisations running AI agents is expected to move from roughly 17% today to more than 60% within two years. As one of our hosts put it, you do not want the fox guarding the chicken. You need some kind of control behind all of it.Microsoft's answer is Agent 365. We spent an hour pulling it apart on a live tenant, with an executive view of the risk and an architect's view of the operations. This is not a sales pitch, even though we finished with a demo of our own. It is an honest look at what Agent 365 is, where it helps, and where it does not. The short version: the good is real, the bad is fixable, and the ugly is strategic.
What Agent 365 actually is
Strip out the marketing and Agent 365 is a chargeable control plane that sits in the Microsoft 365 admin centre and is built on three products you already know: Entra, Purview and Defender. In other words, it is a front end for a set of back-end services rather than a brand new engine. It became generally available on 1 May 2026 at $15 per user per month.
It does three things. It observes, giving you a central registry and inventory of every agent in your Microsoft environment. It governs, by assigning each agent an Entra Agent ID and applying policies and blueprints that determine what permissions an agent has. And it secures, by reusing the Purview data loss prevention and Defender protections you may already run, so agents do not cause harm at runtime.
The detail that matters most is depth, and depth follows identity. Every agent maps to an Entra Agent ID, and having that ID is a requirement for most of the controls. For everything native, meaning agents built in Copilot, Copilot Studio and Foundry, you get full control: deep native integration, real-time DLP, native policy templates, and automatic sync into the Agent 365 inventory. Our architect pressure-tested this live and confirmed that creating a native agent auto-syncs it into the registry.
Third-party agents are a different story. There are four platforms supported out of the box, Vertex, Bedrock, Databricks and Salesforce. For every other vendor, control depends on a software development kit that is free and framework-agnostic, but the vendor has to opt in and publish it. Without that SDK, all you get is network and endpoint discovery. You can see the agent, but you cannot lean on runtime detection from Defender to control it.
The good: a strong Microsoft-native baseline
Three things stand out, and they are worth genuine credit. First, it starts free. Usually a new feature arrives behind a new licence, but here a foundational tier that shows you agent identity, inventory and basic insights is available to every Microsoft Cloud subscriber. Your agents published in Copilot Studio are visible even without a licence, so there is no charge just to see what you have.
Second, it is identity-first and moves toward a predictable cost structure. The Entra Agent ID is the right architectural bet. Per-user pricing is clever, because a consumption-based model on governance would be a roulette wheel. And it is built in-house as a strategic project with serious resources behind it, not bolted on or acquired, which makes it acquisition-safe.
Third, for Microsoft-published agents the integration is genuinely deep. You get real-time data loss prevention and native templates, and because the agent lives natively in the Microsoft environment, the control you have over it is strong. For a Microsoft-only estate, this is a legitimate baseline. The catch is simple: almost no enterprise is Microsoft-only.
Our honest read is that Microsoft has moved quickly here. It is a move in the right direction, and the foundations are sound, but it is not finished and it will take time to mature. If you want to see the baseline in action rather than take our word for it, the walkthrough of Agent 365 on a live tenant is part of the full session on demand.
The bad: maturity and coverage gaps
Agent 365 is sold at a premium but is not finished. Gartner calls it a promising work in progress with a premium price tag, and we agree. The advanced, agent-native controls a control plane is actually for are still missing or in preview. There is no red-teaming yet, so you cannot have an admin or compliance expert pressure-test an agent before it is published rather than after. Intent-based runtime authorisation from Defender is largely in preview. Endpoint shadow-AI detection, the sort of capability that deals with tools like Scout and OpenClaw, is in preview too.
To be fair, that preview status is progress. In the past it was feature first, governance second. Now the feature and the governance around it are arriving in parallel, which is healthier even if the capability is still catching up. The other structural issue is the single control plane. In practice it is four portals, one Agent 365 plus three solution portals, so to use it fully you still need to be an expert in Purview, in Defender and in Entra. The single pane of glass is a front end, not a finished workflow.
Coverage has the same shape, and this is the part that should worry most organisations: the estate you already have is covered least. Agents built in Copilot Studio before the Entra Agent ID existed have no ID, and to bring them into scope they must be recreated after you acquire a licence. Declarative agents, including SharePoint agents, will not get an Entra Agent ID at all. You will see them in the inventory and see who they are shared with, but you will not have the Purview, Defender and Entra security capabilities over them. These are exactly the agents built by ordinary users, not power users, and they are the ones most likely to be over-privileged today.
Copilot Cowork, which Microsoft is actively pushing, is not covered yet either, and local-agent runtime controls remain in preview. And third-party remains discovery, not control, without a vendor SDK. So the agents most likely to be a problem, legacy, citizen-built and multi-platform, are the ones Agent 365 reaches last.
A couple of the live questions sharpened this. One attendee asked which admin role you actually need to run all this. The answer was reassuring on one point and telling on another: no new licence or role is required, a global reader lets you see, and your existing Entra and Purview roles let you configure, but you still drop into Entra, Purview and Defender to set anything up. Another asked whether custom agents built outside Microsoft could be governed. The honest answer was only if they come from one of the four supported platforms, or if the vendor publishes an SDK. Otherwise you get discovery, not control, and for most real estates that is the gap that matters.
The ugly: cost, licensing and lock-in
The ugly is how all of this is licensed. From July 2026 an E3 plus Agent 365 combination is no longer feasible, because Purview has to be part of it, which pushes you toward E5. Then you are looking at the Copilot add-on, the Agent 365 add-on and the Entra Suite, or the E7 bundle at $99 per user per month. Depending on your agreement, that lands at roughly $1,260 per user per year before any consumption costs, which is about a 65% premium over E5 and becomes a permanently higher renewal baseline. That premium is a big part of what is holding organisations back, because the value for the money is still unclear.
Worse, nobody can hand you a clean bill. Microsoft's guidance is to license everyone who interacts with a governed agent, but the free-versus-paid boundary is undocumented and there is no pilot threshold. You might start with a small number of seats, but a 25-seat proof of concept can quietly creep toward enterprise-wide licensing as the agent gets shared. Talk to the specialists who spend their careers on Microsoft licensing, and even they will tell you the boundary is a matter of interpretation. Until Microsoft provides clearer guidance, you cannot reliably build a total cost of ownership for Agent 365, and that is one of the biggest challenges we are seeing right now.
Then there is strategy. Agent 365 deepens single-vendor lock-in at exactly the moment many organisations are trying to keep their options open. They are not betting solely on Microsoft Copilot, Copilot Studio and Foundry. They are also exploring Claude, OpenAI, Gemini, Glean, ServiceNow AI and Salesforce Agentforce. Going all-in on one direction increases your dependence and makes it easier for that vendor to extract more from you over time.
It is also Microsoft-only for runtime control. No vendor can enforce runtime governance on another vendor's infrastructure, so if you want to prevent bad things from happening as they happen across Microsoft, Gemini and ServiceNow AI, everyone brings their own pod and there is no genuine single control plane across platforms. Competitors, meanwhile, are bundling governance into the seat rather than charging extra. Microsoft is pushing hard to upsell customers to E7 or add Agent 365 on top, often on long terms, which is a risky bet when the AI market is moving as fast as it is. Frontier models leapfrog each other every few weeks, and the agent platforms are doing the same. Gartner's advice is essentially wait and see. For context, only about 3.3% of commercial M365 users hold a paid Copilot seat today, roughly 15 million of 450 million on Microsoft's own Q2 FY26 numbers, so this is a hard push into an early market.
Where a vendor-neutral governance layer fits
This is where a governance layer above the platform earns its place, and to be clear it is complementary, not either-or. Rencore is not a runtime control inside any one platform. It is a governance solution that controls the lifecycle of everything you use, starting with Microsoft 365, Teams, SharePoint and OneDrive, extending into Power Platform, and now into AI and agent governance. It connects via the standard Graph API, continuously collects data from each service, and brings it into a single inventory that already includes Copilot, Copilot Studio, Microsoft Foundry and Agent 365 itself, alongside the rest of your estate down to the file level.
The demo followed a simple shape: See, Act, Save, Comply. See is one cross-service inventory for the whole estate, with the same agents you would find in Agent 365 plus far more context, including the knowledge sources an agent consumes and whether a linked SharePoint site carries a sensitivity label. Act is policy-based remediation, including citizen-built agents, with automations that can block, depublish, reassign ownership or route an approval to the agent's owner through a Teams app that looks and feels like Teams. Save is optimising Copilot licensing, pay-as-you-go and connector costs. Comply is being ready for GDPR and the EU AI Act, which begins enforcement shortly, available as SaaS or self-hosted, from an EU vendor in Germany.
One practical point stood out on cost. To pull Agent 365 data into Rencore today you need only a single $15 per user per month Agent 365 licence, not one for every user, which takes away that particular cost burden. Nobody can predict Microsoft's future licensing, but as things stand you can get the data with one licence rather than blanket coverage.
So what should you do
The session closed with a simple decision framework, and it is the right lens. If you are just experimenting and Microsoft-only, start with the free foundational tier plus Purview DSPM for AI, and do not buy Agent 365 broadly yet, because it is still too unclear where Microsoft is heading. If you are scaling agents for mission-critical use, treat Agent 365 as a baseline but augment it, and hedge with a 12-month contract and re-evaluate rather than committing for the long term while the market moves this fast. If you are multi-platform, which most enterprises are, Agent 365 helps but is not sufficient, so put a vendor-neutral governance layer above the platforms. And if cost, oversharing or EU compliance is your real pain, those are gaps Agent 365 does not close at all, so you can start with a governance layer today at any licence tier.
Agent 365 is a reasonable baseline, not a strategy. Govern above the platform. Want the full argument, including the live walkthrough of both Agent 365 and Rencore on a real tenant? Watch the session on demand.