Microsoft launches Agent 365 to govern AI agents as 'double agent' threats emerge in enterprises

Reviewed byNidhi Govil

3 Sources

Share

Microsoft is releasing Agent 365 and Microsoft 365 E7 on May 1, introducing centralized AI governance as companies grapple with rapidly expanding AI agents. With over 80% of Fortune 500 companies using AI agents and 29% operating without IT approval, Microsoft warns of 'double agents'โ€”AI systems potentially hijacked to work against their own organizations through prompt injection and model poisoning.

Microsoft Addresses Growing AI Agent Security Crisis with New Governance Platform

Microsoft is launching Agent 365 and Microsoft 365 E7 on May 1, marking a significant shift in how enterprises manage the explosive growth of AI agents across their organizations

2

. The timing reflects an urgent need: more than 80% of Fortune 500 companies actively use AI agents built with low-code and no-code tools, yet 29% of these agents operate without approval from IT or security teams

2

. Agent 365, priced at $15 per user per month, functions as what Microsoft calls a "centralized control plane for AI" designed to observe, govern, and secure AI agents across enterprises

2

.

Source: CRN

Source: CRN

According to Vasu Jakkal, Corporate Vice President of Microsoft Security, the company now has visibility into more than 500,000 agents running across its own corporate environment, with tens of millions of agents appearing in the Agent Registry within just two months of preview availability

2

. IDC projects 1.3 billion agents in circulation by 2028, creating what Jakkal describes as a critical "visibility gap" that poses substantial business risk

2

.

The 'Double Agent' Threat: When AI Systems Turn Against Their Organizations

Microsoft has introduced the concept of "double agents" to describe AI agents that are manipulated through prompt injection, model poisoning, or other techniques to act against their organization's interests

2

. While Microsoft hasn't observed real-world incidents of agent compromise at scale, the company's AI Red Team has conducted extensive testbed research demonstrating how agents can be exploited to access unauthorized data

2

.

Source: VentureBeat

Source: VentureBeat

The insider risk from AI extends beyond theoretical concerns. Microsoft's research revealed that only 47% of organizations use any security tools to protect their AI deployments

2

. In February, Microsoft's Defender Security Research Team published findings on "AI Recommendation Poisoning," identifying over 50 unique poisoning prompts from 31 companies across 14 industries attempting to inject persistence commands into AI assistants

2

. "Just like insider risk was a big thing with employees, we need to make sure that we don't create that with agents," Jakkal told VentureBeat

2

.

How Agent 365 Tackles AI Agent Visibility and Control Challenges

Agent 365 addresses agent sprawl through three core capabilities: tracking agent activity, managing permissions, and preventing data exposure risk

1

. The platform provides centralized visibility into all managed AI agents across an organization, including Microsoft-built and partner ecosystem agents

1

. The Agent Registry maintains an inventory of agents available through the Microsoft Admin Center and security workflows, while Microsoft Entra Agent ID assigns each AI agent a unique identity within the enterprise environment

1

.

Source: ZDNet

Source: ZDNet

This identity management framework subjects AI agents to the same security protocols as human employees. AI agents are assigned access privileges at or below that of the human issuing the prompt that instantiates them, with conditional access policies extending existing user protections to autonomous AI systems

1

. IT and security teams can audit permissions granted to AI agents, while Microsoft Purview unified data governance now works inside Agent 365 to manage compliance controls and data security risks

1

.

Microsoft 365 E7: Bundling Enterprise AI with Advanced Security

Microsoft 365 E7, dubbed the "Frontier Worker Suite," bundles Agent 365 with Copilot and Microsoft's most advanced security stack into a single $99-per-user-per-month license

2

. This represents Microsoft's first new enterprise license plan in approximately 10 years

3

. The suite unifies M365 E5, M365 Copilot, Agent 365, Entra Suite, and advanced capabilities in Defender, Intune, and Purview

3

.

The $99 price point offers savings compared to purchasing capabilities individually, as M365 Copilot alone costs $30 per user per month, while the Entra Suite is $12 per user per month

3

. Microsoft is also introducing Copilot Cowork in research preview, a collaboration with Anthropic that can orchestrate full workflows and complete actions through embedded agentic capabilities

3

.

According to Jakkal, "Intelligence cannot scale without that trust," emphasizing that AI security and governance tools represent a major opportunity for managed security services providers as business functions across organizations create agents using Copilot Studio and other platforms

3

. Microsoft's security business now protects 1.6 million customers, leveraging more than 100 trillion daily signals and monitoring 24 billion Copilot interactions

1

. Manufacturing, retail, and financial services are leading Microsoft agent adoption as the company reports M365 Copilot now has 15 million paid seats with daily active usage up tenfold

3

.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Donโ€™t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

ยฉ 2026 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo