Microsoft’s Agent 365 helps you spot risky AI agents before they cause trouble – here’s how


gettyimages-2170273841

D3sign/Getty Images

Follow ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • Machine identities are multiplying far faster than human users
  • Agent 365 gives IT visibility into enterprise AI agent activity
  • Microsoft 365 E7 combines Copilot, security, and agent governance

AI can seem exciting, especially when it comes to the productivity improvements AI agents provide in the corporate world. But what’s rapidly dawning on company and IT leaders is that AI agents are also becoming the ultimate insider threat.

In ZDNET’s Special Feature: Cybersecurity in the New AI Era, I outlined how this threat is growing by leaps and bounds. In particular, I showed a statistic that, on average, 82 machine identities (often with high-level network access privileges) are being created for every human identity.

Also: Why enterprise AI agents could become the ultimate insider threat

This enormous management challenge hasn’t gone unnoticed by Microsoft. According to Vasu Jakkal, Corporate Vice President, Microsoft Security, “Fueled by more than 100 trillion daily signals, Microsoft Security protects over 1.6 million customers, more than one billion identities, and 24 billion Copilot interactions, at the speed and scale of Al.”

In that context, Microsoft is announcing Agent 365, a centralized control plane designed to observe, govern, and secure AI agents across organizations. Essentially, this is a system that provides tracking and control over agents across silos, enterprise-wide.

Microsoft is also launching Microsoft 365 E7 (Microsoft likes to call it “ME7”), which is a new enterprise suite that includes Copilot, security tools, and agent management capabilities.

The growing need to secure enterprise AI agents

The incredible speed with which new agents are being deployed is creating a massive governance and visibility challenge for CIOs, CISOs, and security teams.

The visibility issue is important because if you don’t know what an agent is doing or that it even exists, you can’t control it. To drive home the scope of this problem, let’s use air traffic as an analogy.

Back when airplanes were new, there weren’t all that many of them. While accidents did happen, pilots could use their Mark I Eyeballs to identify other planes, especially during takeoffs and landings.

But fast forward a hundred years or so, and the skies are full of aircraft. Imagine if there were no air traffic control and airplanes were trying to take off and land at LaGuardia Airport (probably my least favorite airport anywhere). It would be absolute chaos. There’s almost no way pilots could keep track of everything and avoid disaster.

Agent 365 introduces a unified control dashboard

Microsoft’s Agent 365 is essentially air traffic control for agents. The idea of this tool is to coordinate all the AI agents that have been flying under the radar throughout your network.

Without a unified control dashboard, “IT, security, and business teams don’t have the agent visibility and protection they need for their agents,” says Microsoft’s Jakkal. She continues, “Furthermore, teams often work in silos, making it difficult to understand which agents exist, how they behave, who has access to them, and what potential security risks can exist across your enterprise.”

There are three main areas that an agent control dashboard can manage: tracking agent activity, managing permissions, and preventing sensitive data exposure.

Also: Why enterprise AI agents could become the ultimate insider threat

Here’s another analogy. Microsoft Agent 365 is like an HR department, but for AI agents instead of people. The analogy is pretty strong because Microsoft is creating a framework that subjects agents to the same identity and security management as human employees, including unique IDs.

This credentialing is created with Agent Registry, which maintains an inventory of agents available through the Microsoft Admin Center and security workflows. It’s the AI agent equivalent of issuing each AI agent a badge and a lanyard.

Agent 365 provides centralized visibility into all managed AI agents across an organization, including Microsoft-built and partner ecosystem agents. With this mechanism, IT teams can track, observe, and analyze agent performance, usage, and activity both through detailed reporting and agent mapping.

Identity and access controls for AI agents

Within Agent 365, Microsoft Entra Agent ID assigns each AI agent a unique identity within the enterprise environment. That’s the badge we’ve been talking about.

Identity protection and conditional access policies extend existing user protections to AI agents acting on behalf of users. Here’s an important aspect of that: AI agents are assigned access privileges at or below that of the human issuing the prompt that instantiates them.

Governance is built into identity management tools that limit AI agent access. They lock down capabilities so that only the resources necessary for a given task are made available. Through Agent 365, IT and security teams can audit the permissions granted to AI agents.

These features help mitigate the risks posed by unmanaged identities and excessive agent privileges.

Data protection and compliance for agent activity

Microsoft’s Purview unified data governance, risk, and compliance solution now works inside Agent 365, helping organizations manage data security risks associated with AI agents. Capabilities include:

  • Inline data loss prevention: Blocks sensitive information such as personal identity information (PII) or credit card numbers from being processed by Copilot Studio agents.
  • Information protection: Ensures agents adhere to the sensitivity labels applied to organizational data.
  • Compliance tools: Extend audit, eDiscovery, and records management to AI-generated activity.

By extending Purview into Agent 365, Microsoft is securing the enterprise AI agent landscape with enterprise data governance and compliance controls.

Defending agents from emerging AI threats

According to Jakkal, “There is a growing visibility and security gap, with a risk of agents becoming double agents.” Here, too, she says Agent 365 provides support:

  • Microsoft Defender: Protects against identified vulnerabilities, including prompt manipulation, model tampering, and agent-based attack chains.
  • Security posture management: Detects agent misconfigurations and vulnerabilities before they become attack vectors.
  • Detection and investigation capabilities: Allows organizations to respond to attacks targeting AI agents.

The bad guys are out there. They’re always looking for new ways to wreak havoc. Unsupervised AI agents with escalating access privileges are irresistible to attackers attempting to gain a foothold in your network.

What is Microsoft 365 E7 (ME7)?

If Agent 365 is the control tower for agents in the enterprise, Microsoft 365 E7 is the entire airport. Basically, ME7 is a bundle that, “Enables organizations to accelerate frontier transformation and equips employees with AI that shows up inside real work: email, documents, meetings, spreadsheets, and business applications.”

Also: The biggest AI threats come from within – 12 ways to defend your organization

ME7 includes the following components:

  • Microsoft 365 Copilot: AI assistant embedded across Microsoft 365 apps.
  • Agent 365: Framework for building and running organizational AI agents.
  • Entra Suite: Identity, access, and Zero Trust identity protection.
  • Microsoft Defender: Advanced threat protection across users, devices, agents, and apps.
  • Intune: Endpoint and device management for secure access.
  • Purview: Data governance, compliance, and information protection tools.
  • IQ Platform: Shared intelligence layer providing context and organizational data grounding for Copilot and agents.

Jakkal says, “Copilot, agents, and Agent 365 operate together in the flow of work, grounded in shared intelligence from the Microsoft IQ Platform, so they understand context, history, priorities, and constraints.”

Pricing and availability

Microsoft 365 E7 is priced at $99 per user, per month. Both it and Agent 365 will be generally available on May 1.

Microsoft is also setting some expectations about feature availability. Specifically:

  • Runtime threat protection, investigation, and the ability to hunt for agents that use the Agent 365 tools gateway will enter public preview in April 2026 and remain there through May 1.
  • Detection, investigation, and response for Foundry and Copilot Studio agents are in public preview and will continue to be in public preview on May 1.
  • Likewise, Security posture management for Foundry and Copilot Studio agents will “continue to be in public preview on May 1.”

Security foundation for the agentic era

In my article about agents as the new insider threat, I said, “If it takes a team of interviews and multiple rounds before you hire an employee, it should take the same or even a greater level of care before you ‘hire’ a new agent.”

It appears that what Microsoft is offering in Agent 365 and ME7 are the tools to make that analogy into a functional capability inside enterprises with exploding agent populations. Their new offerings aim to bring agents, users, and enterprise data within a unified security framework.

Microsoft calls this change to an agent-enabled environment “frontier transformation,” leveraging the term “frontier model” for bleeding-edge AI models. If you’re going to have a frontier transformation and you’re going to field thousands of AI agents, you’d better have the security and oversight tools to manage all of that.

Also: How to clean up your digital footprint – and why it matters more than you think

If you’re steeped in the Microsoft ecosystem and you’re fielding armies of AI agents, you’ll probably want to give Microsoft’s new offerings a look.

What do you think about the rise of AI agents inside the enterprise? Does the idea of thousands of software agents acting on behalf of employees concern you from a security perspective, or do you see it as a necessary step toward productivity gains?

Do you think tools like Agent 365 and Microsoft 365 E7 are the kind of governance layer companies will need? Will organizations struggle to keep up with the pace of agent deployment? If you’re working in IT, security, or management, are you already seeing these challenges emerge?

Let us know in the comments below.


You can follow my day-to-day project updates on social media. Be sure to subscribe to my weekly update newsletter, and follow me on Twitter/X at @DavidGewirtz, on Facebook at Facebook.com/DavidGewirtz, on Instagram at Instagram.com/DavidGewirtz, on Bluesky at @DavidGewirtz.com, and on YouTube at YouTube.com/DavidGewirtzTV.





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Spotify aims to provide a consistent listening experience that uses minimal data. As a result, your audio quality might be less than ideal, especially if you’re using a pair of high-fidelity headphones or high-end speakers. Here’s how to fix that.

Switch audio streaming quality to Very High or Lossless

The default audio streaming quality in both the mobile and desktop Spotify apps is set to Automatic, which usually keeps the audio quality at Normal, which is only 96 Kbps. Even though Spotify uses the Ogg Vorbis codec, which is superior to MP3, OGG files exhibit slight (but noticeable) digital noise, poor bass detail, dull treble, and a narrow soundstage at 96 Kbps.

Even worse, Spotify is aggressive about adjusting the automatic bitrate. Even though 4G is more than fast enough to stream high-quality OGG files, even with a weak signal, Spotify may still drop the quality to Low, which has a bitrate of just 24 Kb/s. You will notice such a sharp drop in quality, even on a pair of bottom-of-the-barrel headphones.

To rectify this, open the Spotify app, tap your user image, open “Settings and privacy,” and tap the “Media Quality” menu. Once there, set Wi-Fi streaming quality and cellular streaming quality to “Very high” or “Lossless.”

I recommend setting cellular streaming quality to Very high and reserving Lossless for Wi-Fi, since lossless streaming is very data-intensive. One hour of streaming lossless files can take up to 1GB of data, as well as a good chunk of your phone’s storage, because Spotify caches files you’re frequently streaming. Besides, you’ll struggle to notice the difference unless you’re listening to music on a wired pair of high-end headphones or speakers; wireless connection just doesn’t have the bandwidth needed to convey the full fidelity of Spotify lossless audio.

You might opt for High quality if you have a capped data plan, but I recommend doing so only if you stream hours upon hours’ worth of music every single day over a cellular network. For instance, I burn through about 8 GB of data per month on average while streaming about two hours of very high-quality music over a cellular network each day.

Illustration of a headphone with various music icons around.


How Audio Compression Works and Why It Can Affect Your Music Quality

Feeling the squeeze when listening to your favorite song?

Set audio download quality to Very high or Lossless

If you tend to download songs and albums for offline listening, you should also set the audio download quality to “Very high” or “Lossless.” This setting is located just under the audio streaming quality section.

The audio download quality menu in Spotify's mobile app.

If you’ve got enough free storage on your phone, opt for the latter, but if you’d rather save storage space, set it to Very high. You’ll hardly hear the difference, but lossless files are about five times larger than the 320 Kb/s OGG files Spotify offers at its Very high quality setting, and they can quickly fill up your phone’s storage.

Adjust video streaming quality at your discretion

The last section of the Media quality menu is Video streaming quality. This sets the quality of video podcasts and music videos available for certain songs. Since I care about neither, I set it to “Very high” on Wi-Fi and “Normal” on cellular, but you should tweak the two options at your discretion because songs sound notably better at higher video streaming quality levels.

If you often watch videos over cellular and have unlimited data, feel free to toggle video quality to very high.

Make sure Data Saver mode is disabled

Even if your audio quality is set to Very high or Lossless, Spotify will switch to low-quality streaming if the app’s Data saver mode is enabled. This option is located in the Data saving and offline menu. Open the menu, then set it to “Always off,” or choose “Automatic” to have Spotify’s Data Saver mode kick in alongside your phone’s Data Saver mode.

You can also enable volume normalization and play around with the built-in equalizer

Spotify logo in the center of the screen with an equalizer in front. Credit: Lucas Gouveia / How-To Geek

Last but not least, there are two additional features you can play with to improve your listening experience. The first is volume normalization, which sets the same loudness for every track you’re listening to. This can be handy because different albums are mastered at different loudness levels, with newer music usually being louder.

Since I’m an album-oriented listener, I keep the option disabled. I can just play an album and set the audio volume accordingly, and I don’t really mind louder songs when listening to playlists, artists, or song radios.

But if you can’t stand one song being quiet and the next rattling the windows, visit the Playback menu, enable “Volume normalization,” and set it to “Quiet” or “Normal.” The “Loud” option can digitally compress files, and neither Spotify nor I recommend using it. This also happens with “Quiet” and “Normal,” since both adjust the decibel level of the master recording for each song, but the compression level is much lower and extremely hard to notice.

Before I end this, I should also mention that you can access the equalizer directly from the Spotify app, where you can fine-tune your music listening experience or pick one of the available equalizer presets. If your phone has a built-in equalizer, Spotify will open it; if it doesn’t, you can use Spotify’s. On my phone (a Samsung Galaxy S21 FE), I can only use One UI’s built-in equalizer.

To open the equalizer, open “Playback,” then hit the “Equalizer” button. Now you can equalize your audio to your heart’s content.


Adjusting just a few settings can have a drastic impact on your Spotify listening experience. If you aren’t satisfied with Spotify’s sound quality, make sure to adjust the audio before jumping ship. You should also check the sound quality settings from time to time, as Spotify can reset them during app updates.​​​​​​​

Three phones with a Spotify screen and the logo in the center.


These 8 Spotify Features Are My Favorite Hidden Gems

Look for these now.



Source link