Comparison · agent governance · Microsoft

Microsoft agent governance, measured.

Microsoft assembles agent governance from four products. This page scores that stack across 28 capabilities against the same capabilities in Agen.co — with the sources, the scoring ladder, and the rows Microsoft wins all on the page.

The short answer

  • Microsoft governs agents that carry an Entra Agent ID. Agents that never get one sit outside the scope of a protection rule.
  • Defender blocks flagged agent actions before they execute, against four preset detection types. Agen renders a verdict on every action, against any policy you write, in under 30ms.
  • Entra names a sponsor accountable for an agent's lifecycle. Agen resolves each individual action to the human behind it.
  • Agent 365 is licensed per user on top of an E5 or E7 tier, and governance is operated across six admin surfaces. Agen is licensed per governed agent, in one console.
  • Microsoft is stronger where the suite is the product: first-party depth inside Teams and Outlook, network-layer enforcement, and marketplace breadth.
The long read

What Microsoft agent governance actually is.

There is no single product by that name. It is a capability assembled from four products a large enterprise already owns — and a year ago it did not exist at all. Anyone evaluating this space should score the stack as it ships today.


The four products

Each contributes a different layer, and the seams between them are where most of the evaluation happens.

  • Microsoft Agent 365the registry and the operating surface. It inventories agents, syncs from Microsoft sources, maps their relationships, and frames the work as observe, govern, and secure. It reached general availability for Commercial on a per-user basis on 1 May 2026.
  • Microsoft Entra Agent IDagent identity as a real directory object, with a documented sponsor model, delegated and autonomous access patterns, and access packages with approval routing.
  • Microsoft Purviewdata-loss prevention and audit for agent interactions — block or audit across Teams, OneDrive, SharePoint and email, with an audit record covering agent-to-human, human-to-agent, agent-to-tool and agent-to-agent activity.
  • Microsoft Defenderreal-time protection that inspects agent activity through the agentic loop and can stop a risky action before it executes. The default rule audits; custom rules block.

Three things the suite does better than we do

A comparison that scores the vendor zero on everything is a comparison nobody finishes. Three of the twenty-eight rows below go to Microsoft, and they are not consolation prizes.

  • First-party depth inside the productivity suiteagents built on Microsoft's own stack run inside Teams and Outlook. We govern the suite from outside it; we do not live in it, and for scenarios that depend on being in the client, that difference matters.
  • Network-layer enforcementEntra Internet Access is a genuine control point at a layer we deliberately do not operate. We work alongside it rather than replacing it.
  • Ecosystem and marketplace breadtha partner ecosystem with admin-center deployment is a distribution advantage a focused platform does not have.

Three tests any agent-governance layer has to pass

Agent governance is a crowded word. These three questions separate a layer that governs from a layer that observes, and they are the axes the table is organised around.

  • Be at runtimedoes a decision get made at the moment the agent acts, or after the fact? A record of what an agent did is not the same as a verdict on whether it may.
  • Know the identitycan you resolve any individual action back to a named, accountable human? Not the agent's owner in a registry — the person answerable for this action.
  • Cover everythingdoes it reach every agent, including the ones that never enrolled, were built outside the vendor's stack, or face your customers rather than your employees?

Cost is the fourth axis, and it is the one that decides most deals. A governance layer priced per employee gets more expensive as you hire, not as you deploy agents.

The scored comparison

Twenty-eight capabilities, scored side by side.

Runtime enforcement, identity and accountability, coverage, and what it costs to operate — each scored 0–5 on capability depth against vendor documentation, including the rows Microsoft wins.

Capability depthNoneCompleteMicrosoftMicrosoft Agent 365Entra Agent IDMicrosoft PurviewMicrosoft Defender · Agent 365Agen.co
01 · Runtime enforcement
Verdict rendered at the moment of actionMicrosoftBlocks flagged threats pre-executionCapable3/5Agen.coPer-action verdicts, <30msComplete5/5
Allow / deny enforcementMicrosoftAudit or block rulesCapable3/5Agen.coAllow and deny, every actionComplete5/5
Policy scope — what you can write a rule aboutMicrosoftFour preset detection typesPartial2/5Agen.coAny policy you writeComplete5/5
Blocks a single action without disabling the agentMicrosoftCustom rules block the actionCapable3/5Agen.coAction-level enforcementComplete5/5
Masking or redaction at action timeMicrosoftNot documented for agent actionsBasic1/5Agen.coMasking at action timeComplete5/5
Step-up authentication on a risky actionMicrosoftNot documented at action timeBasic1/5Agen.coStep-up, built inComplete5/5
Human-in-the-loop approval on a risky actionMicrosoftApprovals at access-request timePartial2/5Agen.coBuilt in, per actionComplete5/5
02 · Identity & accountability
Agent has a first-class identity objectMicrosoftDirectory object (Entra Agent ID)Strong4/5Agen.coFirst-class agent identityComplete5/5
Agent identity unified with human and machine identityMicrosoftSeparate object modelPartial2/5Agen.coOne fabric: humans, machines, agentsComplete5/5
A named human accountable for each agentMicrosoftSponsor, transfers automaticallyStrong4/5Agen.coNamed owner, every agentComplete5/5
Each individual action attributed to that humanMicrosoftNot resolved per actionPartial2/5Agen.coAttributed per actionComplete5/5
Authority chain preserved across agent-to-agent callsMicrosoftDelegated access, A2A in FoundryCapable3/5Agen.coFull chain, agent to agentComplete5/5
Access evaluated at action time, not only at grant timeMicrosoftConditional Access at access grantPartial2/5Agen.coJudged in context, per actionComplete5/5
03 · Coverage
Endpoint enforcementMicrosoftDefender for Endpoint, active modeStrong4/5Agen.coAgenShield on the deviceComplete5/5
Browser enforcementMicrosoftEndpoint DLP, Windows devicesCapable3/5Agen.coBrowserShield, early accessCapable3/5
Network-layer enforcementMicrosoftEntra Internet AccessStrong4/5Agen.coNot our layer — works alongsidePartial2/5
Agentless discovery — no SDK, no self-registrationMicrosoftRegistry sync across Microsoft sourcesPartial2/5Agen.coAgentless, 5 surfaces, no SDKComplete5/5
Agents carrying no vendor identity objectMicrosoftOutside governance scopeBasic1/5Agen.coDiscovered, owned, governedComplete5/5
Internal workforce agentsMicrosoftCore scenarioComplete5/5Agen.coWorkforce agentsComplete5/5
External customer-facing agentsMicrosoftInternal workforce agentsPartial2/5Agen.coCustomer-facing agents, same planeComplete5/5
MCP tool governanceMicrosoftWork IQ MCP, customer MCP toolsCapable3/5Agen.coMCP tools governed per callComplete5/5
Data-loss protection on agent actionsMicrosoftPurview DLP, agent unaware of blockCapable3/5Agen.coLeak blocking at action timeComplete5/5
04 · Operate & buy
Pricing unitMicrosoftPer user, on top of E5Partial2/5Agen.coPer governed agentComplete5/5
Prerequisite licensingMicrosoftE5 or E7 requiredPartial2/5Agen.coNo prerequisite tierComplete5/5
Platform cost to govern every agentMicrosoftScales with headcount, plus creditsCapable3/5Agen.coScales with agents, not headcountStrong4/5
Consoles to operateMicrosoftSix admin surfacesPartial2/5Agen.coOne console, one policy planeComplete5/5
First-party depth inside the productivity suiteMicrosoftAgents run inside the clientComplete5/5Agen.coGoverns the suite, doesn't live in itPartial2/5
Ecosystem and marketplace breadthMicrosoftPartner ecosystem, admin-center deployComplete5/5Agen.coFocused platform, not a marketplacePartial2/5
23 rows Agen.co leads2 tied3 rows Microsoft leads
Levels reflect capability depth and supporting evidence. Capability descriptions based on vendor public documentation, August 2026.
What the table shows

One boundary explains most of the gap.

Microsoft's enforcement story got materially stronger this year, and the scores reflect that: a 3 on runtime enforcement, not a 1. Defender genuinely stops a flagged action before it runs.

What it cannot do is reach an agent that never got an Entra Agent ID — the rule-scoping interface only lists agents that carry one. Everything else follows from that boundary and from the unit the whole stack is priced and operated in. Those four consequences are below.

Reading the table

Four consequences, one per group.

Each card is the practical version of a group in the table above — what the scores mean once an agent is actually running in your tenant.

01

Enforcement is scoped to four detection types

Defender stops flagged actions pre-execution — real inline enforcement. But a policy that does not map onto one of four preset detection types has nowhere to live, agents on unsupported tools are not covered, and the default rule audits rather than blocks.

preset detection types4
02

A sponsor is not per-action attribution

Entra's sponsor model is good, and it scores a 4: a named human accountable for the agent, transferring automatically when they leave. But that is an ownership fact recorded once. It does not answer who is accountable for this action, at this moment, against this system.

resolved per actionno
03

The governance perimeter is drawn around what enrolled

Copilot Studio and Foundry agents get an identity automatically. Everything else has to arrive through the SDK or as a pre-integrated partner. The agents nobody registered are the ones you most needed governed.

agents without an IDout of scope
04

Priced per employee, operated across six consoles

Agent 365 is licensed per user with a premium tier assumed underneath it, so the bill tracks headcount rather than agents. Governance then spans six admin surfaces, none of which answers the accountability question on its own.

admin surfaces6
Watch it happen

Every agent discovered. Including the ones no registry sees.

Agentless discovery across five surfaces — IdP, gateway, devices, cloud and registries. Nothing has to self-register to be found, risk-scored and mapped to an owner.

agent discovery · live product scene
What closes the gap

Keep Entra. Add the layer above it.

Entra stays your identity provider, Purview keeps doing classification and audit, Defender keeps protecting endpoints. Agen governs on top: every agent discovered without needing an identity object first, every action judged against your policy, every verdict resolved to the human behind the agent.

Select a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

Methodology

How these scores were reached.

Forty-two capabilities were scored against the ladder in our internal rubric; twenty-eight are published here. Four were dropped for lack of a primary source on either side and are not published on any page. Each score reflects capability depth in the vendor's best available configuration — where a capability requires a premium tier, it is scored at its real depth and the licensing cost is carried in the Operate & buy group instead of penalised twice.

Re-verify by30 October 2026Sources6 primary
Evidence ledger
  1. Microsoft Learn — Entra Agent IDTier AAgent identity object model, agent-user pairing, delegated and autonomous access, sponsor recorded by Copilot Studio, and the licensing prerequisites per capability.
  2. Microsoft Learn — Agent ID governanceTier ASponsors as human users accountable for an agent's lifecycle and access, automatic transfer of sponsorship, access packages with approval routing, and Conditional Access evaluating agent context before access is granted.
  3. Microsoft Learn — Agent 365Tier AObserve, govern and secure framing; agent registry, registry sync and Agent Map; general availability for Commercial on a per-user basis as of 1 May 2026; governance spanning the M365 admin center, Entra, Purview and Defender.
  4. Microsoft Learn — Defender real-time protectionTier AReal-time inspection through the agentic loop with risky actions blocked pre-execution; default rule audits and custom rules block; four detection types; agents on unsupported tools or outside Work IQ MCP are not covered; rule scoping lists only agents carrying an Entra agent ID.
  5. Microsoft Learn — Purview for agentsTier ADLP blocking or auditing for agent-to-human and human-to-agent interactions across Teams, OneDrive, SharePoint and email; the agent instance is unaware of a block; audit covers agent-to-tool and agent-to-agent interactions.
  6. Microsoft Licensing FAQTier BAgent 365 per-user licensing basis and prerequisite tier requirements.

Vendor capabilities change. If a row is out of date or wrong, tell us and we will re-score it — corrections are published with the date they were made.

FAQ

Questions, answered.

What is Microsoft agent governance?
It is a capability assembled from four Microsoft products rather than a single one: Agent 365 provides the registry and operating surface, Entra Agent ID provides agent identity and the sponsor model, Purview provides data-loss prevention and audit for agent interactions, and Defender provides real-time protection that can block a flagged agent action before it executes. Agent 365 reached general availability for Commercial on a per-user basis on 1 May 2026.
Does Microsoft block agent actions at runtime?
Yes, within a defined scope. Defender inspects agent activity through the agentic loop and stops flagged actions before they execute, against four preset detection types. The default rule audits rather than blocks, so enforcement is enabled per custom rule, and agents that rely on unsupported tools or do not integrate with Work IQ MCP are not covered.
Does Agen.co replace Microsoft Entra?
No. Entra stays your identity provider. Agen governs what agents do with that identity, per action, and works with any IdP. Nothing about your existing Entra configuration has to be rebuilt.
What happens to agents that do not have an Entra Agent ID?
They fall outside the scope of a Microsoft protection rule — the rule-scoping interface only lists agents that carry an Entra agent ID. Copilot Studio and Foundry agents get one automatically; other agents have to arrive through the SDK or as a pre-integrated partner agent. Agen discovers agents agentlessly across five surfaces, so an agent does not need an identity object to be found, owner-mapped and governed.
How is Microsoft agent governance priced?
On a per-user basis, with a premium tier assumed underneath it — E7, or E5 with Agent 365 added, or standalone Entra licensing per capability. Because agents are not deployed per employee, the cost tracks headcount rather than the number of agents being governed. Agen is priced per governed agent with no prerequisite tier.
Where does Microsoft score better than Agen.co?
Three rows of twenty-eight. First-party depth inside the productivity suite, because agents built on Microsoft's stack run inside Teams and Outlook while we govern the suite from outside it. Network-layer enforcement, through Entra Internet Access, at a layer we deliberately do not operate. And ecosystem and marketplace breadth. Browser enforcement is a 3–3 tie while our BrowserShield remains in early access.
Does this cover agents outside the Microsoft stack?
Yes. Custom agents, third-party assistants and MCP servers are discovered, owner-mapped and governed on the same policy plane as Copilot and Copilot Studio agents — internal and customer-facing alike, across endpoint, browser, gateway and cloud.
How current is this comparison?
It is scored against vendor public documentation and carries a scheduled re-verification by 30 October 2026. Every published row is backed by at least one primary vendor source, all of which are listed on this page — so any row can be checked against the vendor's own docs rather than taken on trust.

Bring your own comparison.

Send us the rows you would score differently. We will show you the evidence behind ours, and where we are wrong we will change the page.