Article on Implementing Agent 365: How we...

Microsoft's internal IT now manages over 500,000 AI agents via its new Agent 365 platform. The tool centralizes inventory, identity, and compliance to curb agent sprawl as adoption grows.

Categorized in: AI News Management
Published on: Aug 07, 2026
Article on Implementing Agent 365: How we...

Microsoft's internal IT organization, Microsoft Digital, is now managing more than 500,000 AI agents through a new internal platform called Agent 365. The company built the tool to answer a question most enterprises will soon face: how to let employees create AI agents freely without losing track of what those agents do, who owns them, and what data they can access.

Microsoft Digital operates as "Customer Zero" for Agent 365, meaning it tests the product in its own production environment before it reaches external customers. The organization has been working alongside the Agent 365 product team to validate the tool, provide feedback, and develop practices for governing agents at a scale no other company has attempted.

Why Microsoft built Agent 365

The company takes a "self-service with guardrails" approach to its productivity estate. Employees can create agents through a range of platforms, including Microsoft 365 Copilot Agent Builder, SharePoint, Teams, Copilot Studio, and Azure AI Foundry. Each platform has its own tools, back-end systems, and ways to view inventory and usage. As agents began operating across apps and runtime environments, that fragmentation became a problem.

"With agents in action across multiple spaces, managing them is a special challenge," said Jonathan Clare, principal service engineering manager in Microsoft Digital. "It was clear that we needed a silo-buster to govern this new ecosystem effectively."

Agent 365 provides that single view. It centralizes agent inventory, integrates with existing Microsoft tools like Entra for identity, Purview for data compliance, and Defender for threat protection, and surfaces risk signals related to agent behavior, access, and data usage.

What Microsoft has learned so far

One of the central insights from the rollout is that agent administration doesn't require a new IT skill set. It builds on the same foundational experience administrators already use to manage products like Power Platform, SharePoint, and Exchange.

"We're still iterating on the seams between administrators with different responsibilities," said David Johnson, principal PM architect in Microsoft Digital. "Agent 365 is providing the space for AI and identity administrators to work closely alongside their colleagues in security, compliance, and governance."

The company has developed a three-part administrative model: AI administrators oversee the complete agent inventory and lifecycle; identity administrators manage agent identities and access changes; and security, compliance, and governance teams define guardrails and approve what data and permissions agents can request.

Microsoft found that a reliable agent registry is the foundation for everything else. The registry tracks ownership, lifecycle state, creation platform, and user scope. Without it, the company warns, agent sprawl, duplication, and ownerless agents become unavoidable as adoption grows.

"Managing agents begins with having a complete inventory with rich information, like their name, lifecycle status, type, ID, owner, where we created them, and where we're using them," said Mike Powers, an AI administrator in Microsoft Digital. "Once you have that level of clarity, everything else-security, compliance, lifecycle management-becomes much easier to manage."

Visualization is the next layer. Dashboards alone aren't enough at Microsoft's scale, so the organization relies on automation, APIs, and bulk actions to spot patterns and prioritize responses. The tool has helped the company identify ownerless agents, duplication, and unexpected data handling behaviors that were previously difficult to track.

"Agent 365 is saving us time by helping us analyze the kinds of issues that are common in agent management and bringing those to our administrators' attention," said Nate Zimmer, senior product manager in Microsoft Digital. "It acts as a command center that surfaces those issues programmatically, so we're able to prioritize the actions we need to take."

Four priorities for management teams

For organizations just starting to govern AI agents, the guidance from Microsoft Digital comes down to four areas of focus.

Establish a governance rhythm before agents multiply. The hardest part wasn't the technology, according to Garima Tiwari, principal product manager for Agent 365 Customer Zero. It was building a weekly cadence where IT, security, identity, product, and business unit teams could look at the same data and make decisions together.

"When we started, I thought the hardest part would be the technology, but it turned out to be building the weekly rhythm where IT, security, identity, product, and business unit teams could look at the same picture, make decisions from the same facts, and act together," Tiwari said. "My advice to every IT leader is to establish that governance rhythm before your agent count grows faster than your ability to manage it."

Start with visibility, not perfection. You don't need a fully mature operating model on day one. What matters is creating shared visibility into what agents exist, how people use them, and where risks are emerging.

Define roles and handoffs explicitly. Effective agent governance depends on clear coordination between security teams, AI administrators, identity administrators, and platform owners. Microsoft describes it as choreography, not hierarchy.

Treat agent management as an evolution of existing IT practice. Managing agents builds on familiar disciplines like identity, lifecycle, access control, and security rather than replacing them. Agent 365 is an oversight and coordination layer, not a substitute for platform or identity administrator expertise.

For a deeper look at how management teams are adapting to AI-driven workflows, see AI for Management. For more on the technical side of agent administration, see AI for IT & Development.

Why this matters for management

The operational challenge Microsoft describes is not limited to companies with hundreds of thousands of agents. Any organization that lets employees create AI agents will eventually face the same questions: Who owns this agent? What data can it access? What happens when the employee who created it leaves?

The lesson for managers is to put governance in place before those questions become urgent. That means assigning clear ownership for agents, defining risk criteria for publishing, and building a regular review process that includes security and compliance teams. The technology for managing agents is still maturing, but the management practices-clear roles, shared visibility, explicit handoffs-are what will determine whether agent adoption creates value or creates risk.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)