What Microsoft agent governance actually is.
There is no single product by that name. It is a capability assembled from four products a large enterprise already owns — and a year ago it did not exist at all. Anyone evaluating this space should score the stack as it ships today.
The four products
Each contributes a different layer, and the seams between them are where most of the evaluation happens.
- Microsoft Agent 365the registry and the operating surface. It inventories agents, syncs from Microsoft sources, maps their relationships, and frames the work as observe, govern, and secure. It reached general availability for Commercial on a per-user basis on 1 May 2026.
- Microsoft Entra Agent IDagent identity as a real directory object, with a documented sponsor model, delegated and autonomous access patterns, and access packages with approval routing.
- Microsoft Purviewdata-loss prevention and audit for agent interactions — block or audit across Teams, OneDrive, SharePoint and email, with an audit record covering agent-to-human, human-to-agent, agent-to-tool and agent-to-agent activity.
- Microsoft Defenderreal-time protection that inspects agent activity through the agentic loop and can stop a risky action before it executes. The default rule audits; custom rules block.
Where the suite is strongest
Three of the twenty-eight rows below go to Microsoft. Each one follows from owning the productivity suite itself, which is an advantage no independent layer can buy.
- First-party depth inside the productivity suiteagents built on Microsoft's own stack run inside Teams and Outlook. We govern the suite from outside it, which is what lets one policy also reach agents built anywhere else — but where a scenario depends on being in the client, being the client wins.
- Network-layer enforcementEntra Internet Access is a genuine control point at a layer we do not operate. We govern the action rather than the path, and run alongside it.
- Ecosystem and marketplace breadtha partner ecosystem with admin-center deployment gives Microsoft a wider distribution footprint than ours today.
Three tests any agent-governance layer has to pass
Agent governance is a crowded word. These three questions separate a layer that governs from a layer that observes, and they are the axes the table is organised around.
- Be at runtimedoes a decision get made at the moment the agent acts, or after the fact? A record of what an agent did is not the same as a verdict on whether it may.
- Know the identitycan you resolve any individual action back to a named, accountable human? Not the agent's owner in a registry — the person answerable for this action.
- Cover everythingdoes it reach every agent, including the ones that never enrolled, were built outside the vendor's stack, or face your customers rather than your employees?
Cost is the fourth axis, and it is the one that decides most deals. A governance layer priced per employee gets more expensive as you hire, not as you deploy agents.