Microsoft Agent 365: Taming AI Agent Sprawl
Microsoft posted its July 2026 Agent 365 update on 6 August 2026, adding multi-tenant governance as businesses struggle to track their own fleets of AI agents.
Microsoft published "What's new in Agent 365 – July 2026" on 6 August 2026, its monthly update on a product built specifically to let IT departments see and control the AI agents running across their organisation [1]. According to Microsoft's own Agent 365 documentation, the July update added "expanded multi-tenant governance capabilities," letting enterprises manage agents across multiple organisational contexts from one place [2]. Agent 365 itself is not new — it became generally available on 1 May 2026 — but this update is a reminder that the product exists largely because of a problem every business now has: knowing what AI agents are actually running inside it.
What Agent 365 is, and why Microsoft built it
Microsoft describes Agent 365 as "the control plane for AI agents," built around five capabilities: a Registry to discover and catalogue every agent in an organisation, Access Control to set policies on which agents can run and who can use them, Visualisation dashboards showing telemetry across the whole agent fleet, Interoperability with agents from Microsoft, open-source and third-party platforms, and Security features covering threat detection, compliance and data protection [2]. Microsoft's own framing, from its general-availability announcement, is blunt about the underlying problem: "you can't govern what you can't see, and you can't secure what you don't understand — especially when the number of agents is a moving target" [3].
The components behind that pitch
The product is built from named parts: an Agent Registry for central discovery, an Agent Map that lets administrators filter agents by platform, status, publisher, data source and usage, a "Work IQ MCP" that provides governed data, context, skills and tools for grounding agents, Microsoft Entra Agent ID for agent-specific authentication and authorisation, and an Admin Center Dashboard for oversight [2]. It integrates with Microsoft Purview for data security and compliance and Microsoft Defender XDR for threat protection [2].
What "shadow AI" discovery actually finds
One specific capability is worth flagging on its own: Microsoft states that Agent 365 can identify unmanaged local agents running inside an organisation, and names examples including OpenClaw, Claude Code and GitHub Copilot CLI, alongside cloud-hosted agents [3]. In other words, Microsoft has built a tool that can flag competitors' and partners' agent products — not just Microsoft's own Copilot agents — as unsanctioned "shadow AI" if IT hasn't explicitly approved them. Agent 365 also extends beyond Microsoft's own platforms, with support for managing agents across AWS Bedrock, Google Cloud and third-party SaaS applications [3].
Pricing
Microsoft prices Agent 365 as a standalone licence at $15 per user, per month, or as an inclusion in Microsoft 365 E7 [3]. The company states the licence covers "individuals who manage, sponsor, or use agents within the organisation" [3] — a broader definition than a typical per-seat software licence, since it can apply to people who merely sponsor an agent's use rather than operate it directly.
Why this matters
Agent 365 is a governance product for a problem that mostly didn't exist eighteen months ago: businesses now have employees, contractors and departments independently signing up for and deploying AI agents — coding agents, research agents, always-on assistants like xAI's Grok Bot (introduced 11 August 2026) — often without any central record of what has access to what. Microsoft naming rival products like Claude Code and OpenClaw as things its own tool can detect and flag is a clear signal of how it's positioning Agent 365: not as a Microsoft-agents-only product, but as an oversight layer that sits above whichever agents a business ends up using.
Who should care
IT and security teams at any organisation that has allowed multiple departments to adopt AI agents independently are the direct audience — Agent 365 is explicitly a governance and discovery tool, not an agent-building platform. Compliance and data-protection teams evaluating AI agent risk should note the Purview and Defender XDR integrations specifically, since those tie agent oversight into tooling many enterprises already have. Businesses currently on Microsoft 365 E7 already have access to Agent 365 as part of that licence and may not realise it.
Practical implications for buyers and users
For a business without any current visibility into which AI agents its staff are using, Agent 365's discovery function is arguably more immediately useful than its governance controls — you can't set policy on what you don't know exists. Organisations already standardised on Microsoft 365 E7 should check whether Agent 365 is enabled before considering a separate governance tool. Anyone evaluating Agent 365 against a narrower, single-vendor agent management console should weigh the $15-per-user standalone cost against the breadth of multi-platform coverage Microsoft claims, since that breadth is the main differentiator over a Microsoft-only alternative.
Limitations, availability and unresolved questions
Microsoft has not published detailed figures on how many organisations have adopted Agent 365 since its 1 May 2026 general availability, nor independent data on how effectively it actually detects unsanctioned agents in practice. The July 2026 update's "expanded multi-tenant governance capabilities" are described only briefly in the material we could access; Microsoft's own blog post announcing the update was not fully retrievable in the material we reviewed, so some operational detail of the July release itself — beyond the multi-tenant governance headline — could not be independently confirmed here [1]. It's also unclear how Agent 365's discovery of third-party agents like Claude Code is technically achieved, and whether that detection can be disabled by the agent vendor or the end user.
Verdict
Agent 365 addresses a real and growing problem — organisations losing track of the AI agents operating inside them — with a genuinely cross-platform approach rather than a Microsoft-only walled garden. The $15-per-user pricing and E7 bundling make it a realistic addition for enterprises already in Microsoft's ecosystem, and naming specific rival tools it can detect is a useful signal of how seriously Microsoft is treating "shadow AI" as a category. The July 2026 update itself is incremental rather than transformative on the evidence available, and the bigger open question — how well any of this works in a messy real-world estate of agents from a dozen vendors — remains unanswered by marketing material alone.
The current AI Marketing & Automation shortlist
Where this sits in the wider market: our current shortlist for AI Marketing & Automation, what each tool is best at and the main caution to check before committing.
| Tool | Best for | Current position | Important caution |
|---|---|---|---|
| HubSpot Connected growth suite | CRM-centred marketing, AEO and lifecycle operations | HubSpot now connects marketing automation, customer context, AI agents and dedicated answer-engine visibility tooling. | Value depends on data quality and disciplined CRM use, not merely enabling AI features. |
| Jasper Brand content | Governed campaign content across teams | Jasper remains focused on marketing teams that need brand context, repeatable workflows and approvals. | Plans, limits and model availability change frequently; confirm the current vendor page before purchasing. |
| Writesonic AI-search workflow | Content production plus search and AI visibility | Writesonic is relevant to teams combining content operations with monitoring for newer answer-engine channels. | Visibility scores are directional; connect them to qualified traffic and revenue. |
| Semrush Search intelligence | SEO research, competitive visibility and content planning | Semrush remains a broad search and competitive-intelligence platform as teams add AI visibility to established SEO work. | Plans, limits and model availability change frequently; confirm the current vendor page before purchasing. |
| Surfer On-page workflow | Search-aware briefs and page optimisation | Surfer fits teams that want structured on-page guidance inside a repeatable content process. | Optimisation scores do not replace original evidence, expertise or good writing. |
| Copy.ai GTM automation | Repeatable sales and marketing workflows | Copy.ai is aimed at automating go-to-market processes rather than simply generating isolated pieces of copy. | Plans, limits and model availability change frequently; confirm the current vendor page before purchasing. |
| Klaviyo Lifecycle commerce | Ecommerce email, messaging and customer segmentation | Klaviyo combines commerce data, lifecycle automation and assisted campaign work. | Revenue attribution and deliverability need independent monitoring. |
| Canva Campaign creative | Fast delivery of on-brand marketing assets | Canva gives non-design teams a practical layer for adapting AI-assisted creative into channel-ready formats. | Plans, limits and model availability change frequently; confirm the current vendor page before purchasing. |
| AdCreative.ai Paid creative | Rapid ad variations and testing inputs | AdCreative.ai focuses on producing and iterating paid-media creative rather than managing the whole marketing stack. | Measure incrementality and creative fatigue instead of trusting predicted scores alone. |
| Buffer Social operations | Small-team scheduling and social workflow | Buffer remains a straightforward social publishing layer for teams that value simplicity. | Plans, limits and model availability change frequently; confirm the current vendor page before purchasing. |
| n8n Flexible automation | Technical teams building owned AI workflows and agents | n8n combines workflow automation with reusable agents, tools, memory and self-hosting options. | Flexible automation also creates operational responsibility for credentials, logs and failures. |
| Zapier Accessible automation | Connecting common SaaS tools without heavy engineering | Zapier remains the approachable choice when speed of integration matters more than deep custom control. | Costs can rise with task volume and complex multi-step automations. |
Related reading
Sources and verification notes
Primary product documentation checked for this update: