Microsoft gives AI agents an enterprise identity
Inventory, access rights and logs become the foundation of agent governance.

Subject: Microsoft gives AI agents an enterprise identity
Preview: Inventory, access rights and logs become the foundation of agent governance.
Microsoft Agent 365 treats agents as a new class of digital identity. The platform aims to show which agents exist, who owns them, which data they can access and which policies apply to them.
What happened
Agent 365 provides a registry, access controls through Microsoft Entra, observability and security capabilities. It complements Foundry Control Plane: Foundry helps developers build and test, while Agent 365 helps IT and security teams govern the organisation-wide fleet.
Why it matters
A persistent agent can read files, call APIs and act on someone's behalf. It therefore looks less like a software licence and more like a non-human worker that needs an owner, least-privilege access and an auditable activity record.
What is easy to miss
The dashboard is not the fundamental shift. Identity enables authorisation, revocation, accountability and audit. Available capabilities still depend on licences, integrations and agent type.
What to do next
Create a minimum agent register: name, purpose, owner, data, tools, autonomy level, logs and stop condition. Start with agents that send, modify, purchase or publish.
The takeaway
Agent governance starts with an identity, an owner and the ability to revoke access.
Sources
- Primary sourcemail.google.com
- Primary sourcelearn.microsoft.com
- Primary sourcemicrosoft.com
Last reviewed: · By Arnaud Llamas Bravo


