Microsoft Agent 365 has been generally available in the commercial cloud since May 1, 2026. It is expected to reach GCC High in 2026. When it does, every AI agent already running inside your compliance boundary gets a first-class identity, a data governance policy, and a threat detection profile it does not have today.
3
Microsoft services extended to agents: Entra, Purview, Defender
May 2026
Agent 365 general availability, Commercial
2026
Expected GCC High availability
Today
Copilot Studio agents already live in GCC High, ungoverned by Agent 365 until it lands
Agent 365 is Microsoft’s control plane for AI agents. It does not build agents. It governs the ones you already have, by extending three existing Microsoft security services to cover agent identities the same way they cover human ones.
Any agent published through Microsoft 365 channels and registered with an Entra Agent ID appears in the Agent 365 inventory automatically. Agents built outside those channels need to be registered manually.
Microsoft’s own framing for this: “Manage agents alongside employees, using the admin tools you already know.” Observe, secure, and govern every agent with familiar systems, tailored to the unique needs of agentic AI. That phrasing, observe / secure / govern, lines up directly with the Observability, Security, and Governance tabs covered below.
Five existing admin surfaces get extended to cover agents, not replaced by a new one:
Microsoft tool
What it does for agents
Microsoft 365 admin center
Centralized hub to manage users, agents, and settings securely across your Microsoft 365 environment.
Microsoft Entra
Protect agent identities and secure access to apps, resources, internet, and other agents.
Microsoft Purview
Manage, protect, and govern data that agents use and create across your organization.
Microsoft Defender
Extend comprehensive security posture and advanced threat protection to agents.
Microsoft Intune
Apply policies and guardrails for agents across endpoints.
Agent 365 changes what an AI agent is allowed to touch inside your tenant.
Microsoft groups Agent 365’s capabilities into three areas: Observability, Governance, and Security, in that order on the product page. Microsoft’s own framing for the whole surface: “Monitor and manage agents in real time. Protect all agents end-to-end. Establish guardrails for agents and users.” That’s the structure worth teaching to, since it’s how the product itself is organized, not a framework layered on top of it.
Observability: Tracking What Agents Actually Do
The real-time view runs through an Activity Explorer inside Microsoft Purview’s Data Security Posture Management (DSPM) surface, the same posture-management tooling extended to cover agent behavior rather than just user behavior. It logs individual agent activities by type, participant, timestamp, and the channel the activity occurred in, and assigns each one a risk level. In Microsoft’s own product example, an agent’s communication was flagged as an “unethical” activity type, “high” risk, tied to a named participant, and traced to Teams. That is a level of specificity most GCC High tenants currently have none of for their own Copilot Studio agents.
Role-specific oversight extends that view outward: security leaders get agent risk management, business leaders get business-metric and ROI monitoring. Three more named areas, registry, agents map, and agent analytics, sit alongside it.
Governance: Where an Agent’s Lifecycle Gets Controlled
Agent onboarding runs through IT-controlled workflows, with security policy templates applied at creation so an agent starts secure, governed, and compliant rather than getting locked down after the fact. That’s a meaningful difference from how most Copilot Studio agents get published in a GCC High tenant today: created first, governed later, if at all.
Four more capability areas sit alongside onboarding under Governance: integration management, lifecycle management, audit and logging, and data compliance.
The product’s own agent registry shows what this looks like in practice: every registered agent listed with its status (pending review, pending activation, active), the platform that built it (Copilot Studio, Microsoft Foundry), and the channel it’s published to (Copilot, Teams).
Security: Where Identity and Data Protection Live
Access control runs through the Microsoft Entra admin center’s ID Governance access packages, the same mechanism already used to manage human access requests, now extended to cover agent identities. Conditional Access and internet traffic filtering policies that already apply to a person’s account extend to an agent’s the same way, protecting agent identities and preventing breaches by extending those policies from users to agents.
Data security, which Microsoft’s broader product materials tie to Purview sensitivity labels and Data Loss Prevention, is the piece that determines whether an agent can be trusted near CUI at all. Threat protection sits alongside it, extending Microsoft Defender’s advanced hunting and anomaly detection to agent tool calls, not just agent logins.
Copilot Studio’s Agent Builder has been live in GCC and GCC High since roughly April 2026. That means an organization building agents inside a CMMC-scoped tenant today is doing it without Entra Agent ID, without Purview’s agent-aware DLP, and without Defender’s extended detection, because Agent 365 itself has not reached GCC High yet.
That is not a hypothetical risk. It is the current state of any GCC High tenant already experimenting with Copilot Studio agents. An agent with access to a SharePoint library or a Teams channel has the same reach into CUI a person would, without the identity and access controls a person is required to have.
What to Do Before Agent 365 Lands
Do not wait for GA to start. The gap above exists rightnow, regardless of when Agent 365 arrives.
What Changes the Day It Arrives
Agent 365 does not replace your CMMC or NIST SP 800-171 controls. It extends the same identity, data, and threat models those controls already require, to a category of account your System Security Plan may not currently document at all.
Agent 365 is Microsoft’s governance and security layer for AI agents, organized around three areas: Observability, Governance, and Security. It registers agents with an identity, extends Purview data protection to what they access, and extends Defender threat detection to what they do.
No. Agent 365 reached general availability in the Commercial cloud on May 1, 2026. It is expected in GCC High later in 2026.
Yes, once it reaches your environment. Any agent published through Microsoft 365 channels and registered with an Entra Agent ID appears in Agent 365 automatically.
No. It extends identity, data, and threat controls to agents. Your scope, evidence, and documentation still have to account for what those agents can reach.
Inventory the agents already running in your tenant, confirm your DLP and sensitivity labels cover agent access, and assign an owner to each one, since none of that depends on Agent 365 being live to start.
Licensing depends on your current plan. A strategy session is where that gets confirmed for your specific environment.
Agent 365 changes what an AI agent is allowed to touch inside your tenant. Whether your agents are ready for that on day one is a different question. Which one are you certain of right now?