Microsoft 365 Enterprise Blog | Updates, News & Insights

Introducing Orchestry AI & Agents: govern agents in M365

Written by Liz Stanton | Sep 1, 2026, 11:00:00 AM

Open the agent registry in your Microsoft 365 admin center and you'll find a tile labeled Unmanaged agents. Microsoft defines it as the agents created or managed outside Agent 365, without its risk protection and observability. Microsoft will inventory your agents for free and charge you to find out which ones are risky, so that tile is a running count of the agents nobody is governing yet.

Today Orchestry is releasing AI & Agents, a new product area for teams working out how to govern AI agents in Microsoft 365. It brings your agents across platforms into one roster, scores the risk of each one, and governs the content those agents read. It's available now on the Orchestry Enterprise plan, and it runs on the Microsoft 365 licensing you already hold.

What AI agent governance covers, and where most tools stop

AI agent governance has two halves. The first is the agents themselves: what exists, who built it, who can reach it, and what it's able to do. The second is the content and permissions underneath them, because an agent answers from whatever the person using it can already reach.

The tooling in this category tends to stop after the first half, Microsoft's included. Agent sprawl is a visible problem and a roster is a satisfying answer to it. A list of three hundred agents still won't tell you which three are dangerous, and it says nothing about the decade of sharing decisions that decide what any of them can surface.

That ordering matters more than it sounds, because it changes what you fix first. Two agents with identical configuration aren't equally dangerous if one of them is pointed at a site carrying three thousand anonymous sharing links.

Why agent risk scoring sits behind a Microsoft license

The split between what Microsoft gives you and what it charges for is worth understanding before you decide what to buy, because the free half is more capable than most people expect.

The agent registry in the Microsoft 365 admin center gives you a roster across publisher types, ownerless-agent detection, block actions with delete for Agent Builder agents, and a CSV export with more than thirty fields per agent. The risk view is separate. The Risks column, the Agents at risk tile, run-time and active-user metrics, registry sync and Agent Map all depend on an Agent 365 license.

Included with a Microsoft 365 license Requires Agent 365
Agent roster by publisher type Risks column and Agents at risk
Agents without owners Active users and agent run-time
Unmanaged agents count Registry sync to external platforms
Block, and delete for Agent Builder Agent Map
CSV export Custom policies at agent upload

There's a second gap that licensing doesn't close. Per Microsoft's own permissions table, the AI Administrator role gets no access to Defender risks, no access to Purview, and only partial access to Entra. The role that most naturally owns agents can see that a risk exists and can't go and look at it. Investigating means a second role, or a second person.

Agent inventory, risk scoring, and remediation in one roster

Orchestry inventories your agents across platforms into a single filterable roster, with owner names resolved to real people rather than object IDs, and a creation date on every row. Each agent carries a composite risk score from 0 to 100, banded into five tiers from Low to Critical.

The score comes from named governance insights, and the insights that fired on a given agent are shown on the agent itself with a description of each one. So the answer to "why is this agent near the top of my list" reads in plain words rather than arithmetic: it's shared tenant-wide, its owner has left the company, and it reaches an external MCP server. That's the answer a security review can use.

Every insight also works as a filter with a live count next to it. "We have a sharing problem" and "we have three agents shared tenant-wide" lead to very different Monday mornings.

Agents don't float free of the platform they run on, so the roster ships with the Power Platform context around it: environments, DLP policies, custom connectors, and solutions. A custom connector is how an agent reaches a system nobody expected it to reach, and it's usually the least-inspected object in a tenant.

You can also act from the same place you're looking. Delete an agent across all sources from one place, and deleted agents are retained with a Deleted status so your audit trail and trend history survive the cleanup.

For the capability-by-capability walkthrough, including where each report lives in the product, our head of Product Strategy & Innovation covers how the Microsoft 365 agent inventory gets built.

Governing what Microsoft 365 Copilot agents can reach

An agent inherits its reach from whoever's using it, so agent risk is mostly inherited content risk. Cleaning up the roster without cleaning up the content underneath leaves the exposure exactly where it was.

This is the half Orchestry has been governing since before agents existed. The AI readiness dashboard scores your tenant on 13 governance signals across oversharing, governance, and Orchestry safeguards. Each signal passes or fails against a threshold and the score is the share that pass, so no single signal can dominate the number, and it reads every site in the tenant, not a ranked sample of the worst ones. It doesn't need a SharePoint Advanced Management license.

Early tenants scored 23% and 28% on their first scan, before any governance work started.

Underneath the score sit the actions: oversharing detection with one-click remediation at the workspace level, the ability to include or exclude any site from Microsoft Search and Copilot as part of a workspace review, and archival that moves inactive content to cold storage where Copilot can't ground on it. If you've already worked through what Copilot can reach or audited your permissions and sharing links, this is the same job with the AI layer now sitting on top of it.

The AI readiness dashboard is included on every Orchestry plan.

Giving your security team agent risk without giving them everything

Agent governance touches sensitive ground: what content AI reads, who's able to reach it, and a destructive action. Handing someone that shouldn't mean handing them provisioning and lifecycle control at the same time.

Orchestry has a dedicated AI & Agents admin role, assignable to individual users or to groups, that grants agent governance, reporting and actions and nothing beyond them. Every assignment change is written to the access control history, so who was granted it and when stays answerable six months later.

What to look for in an AI agent governance platform

If you're comparing options, these are the questions that separate a roster from governance.

Question to ask Orchestry Microsoft native
Does it grade risk, or only flag it? Composite 0 to 100 score, five tiers High-severity risk count, with Agent 365
Can it tell you why a score landed there? Named insights shown on the agent Risk types listed, investigated elsewhere
Does it cover the platform agents run on? Environments, DLP, connectors, solutions Power Platform admin center, separately
Can you act from the same screen? Delete across all sources, from one place Actions vary by agent type
Does it govern the content agents read? 13-signal readiness plus oversharing remediation Purview and SAM, licensed separately
What licensing does it need? Existing E3 or E5 Agent 365 for the risk view

Rated against Microsoft 365 E3 and E5. Microsoft keeps extending its native tooling, and the agent registry and Agent 365 are converging into a single control plane, so this comparison is a snapshot rather than a settled state.

Where Orchestry takes AI agent governance next

This is just the first step in AI and agent governance for Orchestry. Orchestry is building towards much more.

  • Content grounding. The specific documents an agent's answers draw on, a level below the sources it's pointed at, so you fix the few thousand files that matter instead of cleaning a hundred thousand sites.
  • Scheduled agent review. Owned by the people who built the agents, on the same review model that already governs workspaces and OneDrive.
  • AI usage and cost. Where AI is earning its cost, what it touches, and what it's worth.

How to govern AI agents in Microsoft 365: common admin questions

How do you govern AI agents in Microsoft 365?

Governing AI agents in Microsoft 365 takes two things: an inventory of the agents themselves, with enough detail to tell which ones carry risk, and control over the content and permissions those agents read. The Microsoft 365 admin center provides the inventory. Orchestry adds the risk scoring, the Power Platform context, remediation, and the content layer underneath, on the E3 or E5 licensing you already hold.

What is AI agent governance?

AI agent governance is the practice of knowing which AI agents exist in your tenant, which of them carry risk and why, and being able to act on that, together with governing the content and permissions those agents read. The first part is an inventory problem. The second is a permissions and oversharing problem that predates agents entirely.

Do you need an Agent 365 license to govern agents in Microsoft 365?

Not with Orchestry. Orchestry's agent governance runs on the Microsoft 365 E3 or E5 licensing you already hold, with no Agent 365 entitlement and no per-user Microsoft add-on. Microsoft's own risk view, including the Risks column and the Agents at risk tile, does require Agent 365.

How does Orchestry decide which agents are risky?

Each agent gets a composite risk score from 0 to 100, banded into five tiers from Low to Critical. The score is produced by named governance insights covering who can reach an agent, whether anyone still owns it, what it's able to do, and what it grounds on. The insights that fired are shown on the agent itself, so you can read the reason rather than infer it.

Can Orchestry remove an agent?

Yes. You can delete an agent across all sources from one place. Deleted agents are retained in the inventory with a Deleted status, so your audit trail and trend history stay intact after a cleanup.

Does Orchestry govern only agents, or other AI too?

Both. Agents are governed directly through inventory, risk scoring and remediation. Other AI, Copilot included, is governed through the content it can reach, using readiness scoring, oversharing detection, Search and Copilot visibility controls, and archival. The conditions Orchestry measures apply to any AI reading your Microsoft 365 content.

The first move in AI agent governance

How to govern AI agents in Microsoft 365 comes down to two questions: which agents exist, and what they can reach. The Unmanaged agents number in your admin center isn't going down on its own, and the content underneath those agents is the part that decides how much it matters.

AI & Agents is available now on the Orchestry Enterprise plan, and the AI readiness dashboard is included on every plan, so you can score your content posture before you decide anything about agents. If you're ready to see what Orchestry would look like in your environment, request a demo and we'll go through it with you.