Microsoft is turning AI agents into first-class security objects. With Microsoft Agent 365 and Defender, security teams can build an inventory, assess posture, inspect runtime behavior, block supported high-risk actions, and investigate agent activity alongside identities, devices, applications, and incidents.
The change is operational as well as technical. Effective July 1, 2026, Microsoft moved the listed security capabilities for Copilot Studio and Microsoft Foundry agents behind an Agent 365-eligible license. Tenants that previously relied on Defender for Cloud Apps or Defender for Cloud alone need to confirm licensing and recheck their enablement.
The key distinction: Agent 365 is the control plane and registry; Defender is the security operations layer. Neither automatically makes every agent, tool, permission, or execution path safe.
What changed for Microsoft customers
| Change | Current meaning | Action |
|---|---|---|
| Agent 365 reached general availability | Microsoft now positions Agent 365 as the enterprise control plane for observing, governing, and securing agents across Microsoft and supported partner ecosystems. | Decide which agents must be registered, who owns the registry, and how lifecycle status is enforced. |
| Jul 1 licensing transition | Listed Copilot Studio and Foundry security capabilities require an Agent 365-eligible license. | Verify entitlements, trials, Defender settings, and continuity of visibility. |
| Security for AI consolidated | Microsoft documents a consolidated Security for AI Agents enablement path in Defender, supported by Agent 365 observability and registry data. | Confirm connectors and supported agent platforms are actually onboarded. |
| Newer controls remain mixed-status | Agent 365 is generally available, while several agent-risk, local-agent, multicloud, and runtime capabilities are documented as preview or platform-dependent. | Track availability by capability instead of labeling the entire stack simply “GA.” |
The four layers Defender can provide
| Layer | What it helps answer | Typical output |
|---|---|---|
| Discovery | Which supported agents exist, where they run, who or what identity they use, and which tools they can reach. | AI Assets inventory, Agent 365 registry context, and Advanced Hunting data. |
| Posture and risk | Which agents combine risky access, weak instructions, autonomy, sensitive data, tool exposure, or active alerts. | Risk levels, indicators, recommendations, relationships, and prioritization context. |
| Runtime protection | Can a supported risky prompt, tool call, or response be audited or blocked before the action completes? | Audited or blocked behaviors, policy matches, and behavior records in Defender. |
| Detection and investigation | What happened, which agent and user were involved, what tool was invoked, and what the possible blast radius is. | Alerts, correlated incidents, entity relationships, Advanced Hunting queries, and response workflows. |
How Microsoft assesses agent risk
Microsoft Defender’s agent posture model combines active risk indicators. These can come from an agent’s configuration, instructions, tools, permissions, runtime activity, endpoint and user context, or active security alerts.
Examples in Microsoft’s documentation include weak instructions, high usage, indirect prompt-injection exposure, privileged business-system access, and an active threat. For local agents, the surrounding context matters: running for a critical user, on a critical or vulnerable device, or with privileged software-development access can raise the potential impact.
A high-risk rating is not automatically proof that an agent was built incorrectly. A public support agent may intentionally accept unauthenticated traffic. An operations agent may need write access to a business system. Those facts still increase exposure, so the right question is whether the business purpose, permissions, monitoring, approvals, and compensating controls justify the risk.
Review risk level and recommendations together. Microsoft notes that a high-risk agent may have no available recommendation when an indicator is intentional or not directly remediable, while a lower-risk agent can still have a useful configuration recommendation.
Runtime protection has real coverage boundaries
Defender can inspect activity through the agentic loop and, for supported paths, block risky actions before execution. Coverage differs by agent type:
- Agent 365 tool invocations: Microsoft documents protection through Work IQ MCP for supported tool calls, including supported customer MCP tools onboarded to Agent 365. Agents using unsupported tools or paths outside that integration are not covered automatically.
- Copilot Studio agents: Defender evaluates supported tool invocations after Copilot Studio is connected in the Security for AI setup.
- Local AI agents: These require separate endpoint onboarding. Defender for Endpoint must run in active mode for runtime protection on supported endpoints.
This is why an inventory cannot stop at the agent name. For each important agent, document its identity, data, tools, MCP servers, platform, runtime, user population, supported protection path, and any execution route Defender cannot see.
Start in audit before you block
Microsoft’s current design includes a default audit rule for cloud agents. Matching behavior is recorded without stopping the action, which gives the security team a baseline. Custom rules can then block selected detection types and be scoped to all or specific agents.
A controlled rollout should:
- Run in audit long enough to understand normal tool use and false positives.
- Choose high-confidence threats where blocking is safer than allowing execution.
- Test the block against a nonproduction or low-impact agent.
- Define who receives the event, who can disable the rule, and how business operations continue.
- Expand scope only after the agent owner and security team agree on the result.
Defender records audited and blocked activity as behaviors, including the agent, user, tool, and reason. That creates useful hunting and automation data, but it also changes alert behavior: Microsoft notes that near-real-time alerts continue in audit mode, while a blocking rule may prevent a separate near-real-time alert for the covered agent. Build dashboards and response playbooks with that distinction in mind.
Prompt evidence needs a privacy decision
Defender can include suspicious prompt or response snippets as alert evidence. Microsoft says sensitive data and secrets are redacted, but also cautions that the conversation itself may remain sensitive. Administrators can control prompt-evidence collection.
Before enabling broad collection, decide:
- Which security roles can view prompt evidence
- How incidents containing customer, employee, legal, health, or financial context are handled
- What retention and export rules apply
- How investigators avoid copying sensitive evidence into tickets and chat
- Whether regional, labor, or contractual requirements change the design
A practical 30-day rollout
Week 1: Confirm the control plane
- Validate Agent 365 licensing and the July 1 transition status.
- Confirm Security for AI Agents is enabled as intended.
- Connect the Microsoft 365 app path and Copilot Studio where applicable.
- Identify local agents that require Defender for Endpoint onboarding.
Week 2: Reconcile the inventory
Compare the Agent 365 registry, Defender AI Assets, Copilot Studio environments, Foundry projects, endpoint discoveries, SaaS records, and procurement data. Assign an owner and business purpose to every material agent. An unowned agent should not retain broad access simply because it appears in a Microsoft inventory.
Week 3: Prioritize posture
Start with agents that can write to important systems, use maker or user credentials, access sensitive data, run without approval, serve many users, or already have active alerts. Reduce unnecessary permissions and tool scope before relying on detection to catch misuse.
Week 4: Tune runtime controls
Review audit behaviors, select a small set of high-confidence blocking scenarios, test response ownership, and document unsupported paths. Establish a monthly operating review for new agents, changed tools, risk movement, incidents, exceptions, and stale registrations.
What Defender does not replace
- Identity design: Agents still need unique, scoped identities, least privilege, credential lifecycle, and Conditional Access where supported.
- Data governance: Purview labels, DLP, retention, access reviews, and clean permissions remain necessary.
- Secure build practices: Instructions, tool contracts, input validation, secrets handling, dependency security, and red-team testing remain the builder’s responsibility.
- Business approvals: High-impact actions still need appropriate human review, separation of duties, and transaction controls.
- Complete third-party coverage: Every agent platform, endpoint, MCP server, or tool path must be verified. Registration does not guarantee runtime inspection.
Frequently Asked Questions
What does Defender add to Agent 365? Defender provides the security operations layer: supported discovery, risk and posture, runtime audit or blocking, threat detection, incident correlation, and hunting.
Did licensing change? Yes. Microsoft states that the listed Copilot Studio and Foundry agent-security capabilities require an Agent 365-eligible license as of July 1, 2026.
Is every capability generally available? No. Agent 365 is generally available, but several newer agent-risk, local-agent, multicloud, and runtime features remain preview or platform-dependent. Verify each capability that matters to the design.
Does Defender protect every tool call? No. Coverage depends on the agent type, connection, supported tool path, and runtime. Unsupported tools or paths outside the supported integration are not automatically protected.
Should we enable blocking immediately? Usually not across the full estate. Begin with audit, understand normal behavior, and introduce tested blocking rules for high-confidence scenarios.
Build an AI agent security operating model
Accred Consulting can help reconcile agent inventory, identity, permissions, Defender coverage, Purview controls, runtime policies, and incident ownership into one practical Microsoft 365 governance program.
Review Your Agent Security