News
Microsoft Puts Agent 365 to Work Managing Its Own AI Agent Explosion
- By Chris Paoli
- August 19, 2026
Microsoft’s growing population of internal AI agents is giving the company a large-scale test case for the governance problems enterprises are likely to face as agent adoption accelerates. With hundreds of thousands of agents operating across its environment, Microsoft is using Agent 365 to establish a centralized inventory and identify who owns those agents, how they are being used and where potential risks are emerging.
The system gives Microsoft administrators a common control layer for agents created through Microsoft 365 Copilot, SharePoint, Teams, Copilot Studio, Microsoft Foundry and third-party platforms. By combining ownership and lifecycle information with usage and risk signals, Microsoft is trying to replace manual oversight with a governance model that can operate at the scale of its expanding agent ecosystem.
At the core of this shift is visibility, where Agent 365's registry automatically collects metadata from supported platforms, including an agent's owner, creation platform, publishing surface, lifecycle state and intended users. Microsoft Digital will continue to validate that inventory for accuracy and reconcile discrepancies with product teams.
"Managing agents begins with having a complete inventory with rich information, like their name, lifecycle status, type, ID, owner, where we created them, and where we're using them," Mike Powers, an AI administrator in Microsoft Digital, "Once you have that level of clarity, everything else -- security, compliance, lifecycle management -- becomes much easier to manage."
The registry helps administrators identify ownerless, unused or duplicate agents while showing which tools employees use to build them. It can also highlight agents experiencing rapid adoption, which may indicate either business value or emerging risk.
Microsoft said one of its newest agents, Cowork, became its most widely used agent within weeks. Using Agent 365, administrators analyzed session activity and location information for Cowork's 58,000 active users in minutes.
The scale of Microsoft's deployment makes manual reviews impractical. Instead, the company is combining dashboards with automation, rules, APIs, scripts and bulk actions to prioritize agents based on permissions, connectors and usage patterns.
"Agent 365 is saving us time by helping us analyze the kinds of issues that are common in agent management and bringing those to our administrators' attention," said Nate Zimmer, senior product manager at Microsoft Digital. "It acts as a command center that surfaces those issues programmatically, so we're able to prioritize the actions we need to take."
The implementation also changes how administrative teams work together. Microsoft is developing a three-part model involving AI administrators, Agent Identity administrators and security, compliance and governance teams. Agent 365 supplies shared context while Entra manages identities, Purview provides data protection and Defender monitors runtime threats.
That builds on Microsoft's broader responsible AI program, which requires internal AI initiatives to undergo impact assessments based on principles such as fairness, safety, transparency, privacy and accountability. The company uses a centralized workflow to register projects and guide developers through reviews involving responsible AI, security and privacy specialists.
Microsoft acknowledged that its Agent 365 operating model remains unfinished. Lifecycle support, risk signals and automation capabilities are still evolving, with Microsoft Digital acting as the product's "Customer Zero" and providing feedback to the development team.
"When we started, I thought the hardest part would be the technology, but it turned out to be building the weekly rhythm where IT, security, identity, product, and business unit teams could look at the same picture, make decisions from the same facts, and act together," said Garima Tiwari, principal product manager for Agent 365 Customer Zero.
Microsoft released Agent 365 in May as a stand-alone service priced at $15 per user per month and as part of Microsoft 365 E7. The platform supports Microsoft, third-party and locally running agents as the company seeks to address what it calls "agent sprawl."