
Spotlight
Alasdair Murray, Chief Technology & Product Officer
Microsoft Agent 365 integrates agents into the existing identity and governance framework of Microsoft Entra, marking an important architectural advance. This approach shifts organisational focus from technology to outcomes like scale, risk, and compliance.
Microsoft Agent 365 is now generally available, but the significance is not the launch itself. It is the architectural decision behind it. Microsoft has chosen to extend its existing identity control plane to agents, anchoring them in Microsoft Entra rather than creating a parallel AI governance model. That choice determines whether agents remain isolated experiments or become operable, governable components of an enterprise operating model, and it fundamentally changes the conversation organisations can have about scale, risk, and control.
Rather than starting with tools, features, or deployment models, leaders can start with outcomes. Questions of scale, risk, compliance, productivity, and operating model come first. Technology then follows as the enabler.
This is not the creation of a new or exceptional category of identity. It is the extension of established identity principles to agents. In practice, that means agents sit within familiar control structures, lifecycle expectations, and risk disciplines.
I view this as the right direction because it enables outcome‑led conversations, not technology‑led ones.
Agents Are Not a Special Case. They Are a Scaling Problem
Every leader eventually encounters the same constraint:
What works in isolation fails at scale. (A principle rooted in Russell Ackoff’s systems thinking)
Agents are no exception.
Once agents move beyond experimentation, they become persistent actors. They consume data and APIs, hold privilege, and directly influence operational and regulatory risk. At that point, the question is no longer whether an agent can perform a task. The question becomes whether the organisation can govern the outcome consistently and under change. Agent 365 matters here because it brings agents into the same identity and governance foundations already relied upon for people, applications, and services. Many organisations expected agents to require an entirely new governance layer. In practice, the harder work is extending existing discipline to a new class of actor.
Entra Turns AI Capability into a Sustainable Platform
What stands out in Microsoft’s approach is that it does not ask organisations to invent new governance models. Instead, it reinforces the models that should already exist and makes them applicable to agents.
Identity lifecycle is a prerequisite
If an organisation cannot clearly explain who owns an agent, why it exists, and when it should be retired, the issue is not AI readiness. It is identity maturity. This is where leadership intent meets operational reality. Ownership, sponsorship, expiry, and retirement are not administrative hygiene. They are the mechanisms that keep automation aligned to organisational outcomes.
Conditional Access becomes the control mechanism
Conditional Access is where identity becomes part of organisational decision‑making at runtime. In an administrative model, identity is largely static. Accounts are created, roles are assigned, and access persists until a review occurs. Control is periodic and retrospective. Identity records what something is, but it does not govern behaviour at the point of action.
Conditional Access changes this by making identity a runtime decision point. Every access request, whether from a human or an agent, is evaluated in context. Policy takes into account what is being accessed, the conditions under which the request is made, and the risk signals present at that moment.
For agents, this distinction is critical. Agents operate continuously and often with non‑trivial privilege. Without Conditional Access, access is assumed once granted. With Conditional Access, access remains conditional and continually justified. This is what allows leaders to approve agent adoption without approving uncontrolled risk. This is why anchoring Agent 365 in Entra is significant. Agents do not sit outside the control plane. They are governed by it.
Identity protection supports platform resilience
No responsible leader assumes their systems will never be misused. The practical implication of bringing agents into an identity‑first model is that detection, response, and recovery can follow the same patterns already used for other identities. This is how resilience is built, not by adding more capability, but by extending proven control mechanisms.
Governance and compliance are core requirements
A recurring failure in technology programmes is treating compliance as something to address later.
Once agents become material to how work is performed, governance becomes a requirement. Organisations need clear attribution, auditability, and the ability to demonstrate control under scrutiny. Regulators, auditors, and boards do not distinguish between human and non‑human actors. They distinguish between controlled and uncontrolled risk.
Why This Resonates with Leadership
In our work with clients, we repeatedly see the same progression as organisations move from owning capability to operating it responsibly. Licence discussions lead to value discussions. For boards, the question is whether agent adoption increases or reduces unmanaged risk. For regulators and auditors, the question is whether accountability and control can be demonstrated. For operating model owners, the question is whether agents can be scaled without creating fragility.
Agent 365 matters because it allows those questions to be answered using existing control structures, rather than introducing a new and unproven governance surface.
What leaders should consider next
Agents are becoming actors within every organisation. The question is no longer whether they will appear, but how many are already in use and where they are operating. So the first real challenge with agents is not policy or platform, but visibility. When leaders ask how many agents are operating, who owns them, and what they can access, the answers are often unclear.
In practice, adoption runs ahead of control and usage ahead of monitoring. That gap, between value realised and discipline applied, is where risk accumulates. Testing whether existing identity and governance assumptions hold under real agent usage is therefore one of the most valuable steps organisations can take once experimentation gives way to operation.
Blog
Microsoft 365 E7: What it really means for AI Governance and Identity
Microsoft 365 E7 marks a shift from AI adoption to AI governance, bringing identity, security, and automation together to help organisations scale AI safely, securely, and with full operational control.

Stay Ahead of Identity, Security & AI Governance
Practical insights, real-world experiences, new research, and exclusive event invitations from the identity specialists helping organisations navigate transformation with confidence.









