Microsoft gives AI agents an enterprise identity

Inventory, access rights and logs become the foundation of agent governance.

Blue enterprise AI agent wearing a digital identity badge among access permissions and audit trails.
Share this article

Subject: Microsoft gives AI agents an enterprise identity

Preview: Inventory, access rights and logs become the foundation of agent governance.

Microsoft Agent 365 treats agents as a new class of digital identity. The platform aims to show which agents exist, who owns them, which data they can access and which policies apply to them.

What happened

Agent 365 provides a registry, access controls through Microsoft Entra, observability and security capabilities. It complements Foundry Control Plane: Foundry helps developers build and test, while Agent 365 helps IT and security teams govern the organisation-wide fleet.

Why it matters

A persistent agent can read files, call APIs and act on someone's behalf. It therefore looks less like a software licence and more like a non-human worker that needs an owner, least-privilege access and an auditable activity record.

What is easy to miss

The dashboard is not the fundamental shift. Identity enables authorisation, revocation, accountability and audit. Available capabilities still depend on licences, integrations and agent type.

What to do next

Create a minimum agent register: name, purpose, owner, data, tools, autonomy level, logs and stop condition. Start with agents that send, modify, purchase or publish.

The takeaway

Agent governance starts with an identity, an owner and the ability to revoke access.

Sources

  1. Primary sourcemail.google.com
  2. Primary sourcelearn.microsoft.com
  3. Primary sourcemicrosoft.com

Editorial methodology

Last reviewed: · By Arnaud Llamas Bravo

Tell me what your team needs.

Share the essentials and I’ll get back to you with the most useful next step.