Independent perspectives. A connected world.About the publication ↗
G↗GLOBALTECHRANKS.TECHNOLOGY IN PERSPECTIVE
Cybersecurity

Microsoft Introduces Agent 365 to Govern Enterprise Agents

Microsoft introduced Agent 365 on November 18, 2025 as a control plane for managing AI agents across an organization. Its announcement describes an inventory of agents, access controls, observability and security capabilities built around the enterprise systems Microsoft already supplies.

Microsoft Introduces Agent 365 to Govern Enterprise Agents

Microsoft introduced Agent 365 on November 18, 2025 as a control plane for managing AI agents across an organization. Its announcement describes an inventory of agents, access controls, observability and security capabilities built around the enterprise systems Microsoft already supplies.

The launch article positions governance as a requirement for agents created through Microsoft tools, third-party platforms and open-source frameworks. The core proposition is visibility and control over a growing collection of software workers.

An agent needs an owner

The administrative problem is easy to describe. A team connects an agent to a useful resource, another team builds something similar, and nobody has a reliable view of which credentials and permissions are still active. Each experiment may appear manageable on its own while the combined environment becomes difficult to inspect.

An inventory can make those relationships visible. It does not, by itself, decide whether the access is appropriate. Someone must own the agent's purpose, approve its permissions and take responsibility when the purpose changes.

GlobalRanking's analysis is that a meaningful registry should connect each entry to an actual operating decision. A name and a count are less useful than a clear answer to who can change the agent, which resources it may use and how it can be disabled.

Governance has to follow the work

An agent may read a document, call another service and produce an output that somebody else acts on. Looking only at the final response can miss the access and decisions that preceded it.

For an IT team, this means testing whether logs explain the sequence well enough to investigate a problem. A dashboard full of events can still leave the central question unanswered: why did this particular agent have authority to perform that action?

The company's stated controls address parts of that problem. Buyers should assess them against the workflows they intend to run, especially where agents cross application boundaries. A control that covers one system well may depend on additional integration elsewhere.

Existing administration is an advantage, with limits

Organizations already using Microsoft's identity and management services may find it practical to evaluate governance through that environment. Familiar administration can reduce the work of introducing another tool.

It should not become a reason to skip coverage checks. A business still needs to know which agents are discovered automatically, which require registration and which activities remain outside the available view. Those details determine whether the inventory represents the operating environment or only the part connected to it.

Agent 365 puts a recognizable enterprise problem at the center of the agent discussion. The useful measure of success will be whether administrators can make and enforce better decisions about software acting for the business, rather than simply count more agents on a screen.

Image: Microsoft

← Back to the latest