336 - Governing the Ungoverned: Agent 365 and Entra Agent ID
31m 16s
In this episode of Control Alt Azure, Tobias and UC discuss the rise of agentic engineering and Microsoft's new offerings: Agent 365 and Entra Agent ID. UC shares his experience from the Microsoft MVP Summit in Seattle, noting the challenges of jet lag and the difficulty of meeting everyone due to the event's distributed locations. Tobias contrasts this with the arrival of spring in Sweden, which lifts his mood. The core discussion centers on how agentic engineering has evolved from "vibe coding" prototypes to a structural shift where engineers orchestrate agents rather than write code manually. UC highlights that his team achieved an 800% increase in output by adopting agentic workflows, emphasizing that agents are now integral to engineering, not just assistants. Agent 365 is described as a unified control plane for managing AI agents within the Microsoft ecosystem, offering registry, access control, interoperability, and security integrations with Purview and Defender. It is designed for IT pros to govern agents at scale, though it is limited to Microsoft environments. Entra Agent ID serves as the identity layer beneath, giving agents their own identities for zero-trust governance, conditional access, and accountability. This prevents agents from using user permissions and causing unintended damage. The hosts note that many organizations are unprepared for the shadow IT risks of agent proliferation, and that the $15 per user per month licensing cost for Agent 365 standard will be a key consideration. Overall, they view these tools as a natural extension of existing Microsoft security and management frameworks, rather than a completely new approach.
[MUSIC] >> Hey there and welcome to another episode of Control Alt Azure. This is a show where we talk about all things, Microsoft Technology. I'm Tobias and I'm back with UC. What's up? >> Hey Toby, I'm back from my travels to Microsoft MVP Summit. I think I mentioned this couple of episodes ago. Long flights, usually if you fly from Helsinki to Seattle, this time of the year, you don't get direct flights. For me, it was 10, 11 hours to Dallas, and then three or four hours to Seattle. It's a similar route back if you go to New York or Heathrow. Time difference, 10 hours. This was the first time I used my garment watch to keep reminding me, throughout the week on what sort of jet lag do I still have? Every morning, it's telling me you can expect severe jet lag. Right now, back home, I think I've been home for three days now. I'm still about three and a half hours on the red in terms of jet lag, but I'm managing it quite well because we have a lot of sunshine now in Finland. But the week was great. I met lots of people, but not everyone I wanted to meet because the event is around multiple locations on campus. So you simply cannot visit every location in there. Back in the day, you would go to Bellevue in the evening. You would meet everybody there because everybody would be staying at the hotel's close to Bellevue. But now with Airbnb, there's less of a chance for that. And last final note, my kids only wanted me to bring twinkies. I'm not sure if it's a tick-tock thing. They said, "Dad, bring twinkies." So I got a few boxes of those, one extra box. And we tried one with my colleague while in Redmond. And let's just say there's a lot of sugar in those. Yeah, no, I can imagine. Well, great that you brought some of those back on my end. Spring is here. So yesterday was my first day working from the terrace. Outside in the sun. Good vibes, lots to do. And hearing the birds chirping while knocking out some work. It's pretty amazing. So not much else is up here since the last time we met. Except, of course, for those birds that are actually up right now. I'm happy to get some better weather, hopefully ahead. And hopefully this also means I can update you all on the greenhouse situation at some point. This year, I promise not to speak about it in perhaps 20 episodes. Because I do have an interest. I huge interest in my greenhouse and the garden. And also going outdoors as some of you probably have noticed. This year, I'm going to be a little bit more light on that. But I am just in a great situation, great mood with spring coming. Great weather where I live in Sweden is something that we anticipate every year after winter. Now we've finally arrived. It's a metrological spring, which means it's been so and so warm for 24 hours continuously for so many days, whatever. Don't know the exact values there. But it's hot enough for the grass to now start growing. And the birds are chirping and the sun is out and the sky is blue. There are no problems in life right now. And it's amazing. That sounds awesome. We are following you by two months or so. So ask me again in late May. I will relay the same information. So today our focus is on the Microsoft agent 365 and to a degree, Entra agent ID. And we've mentioned both of these initially. I recall first for agent ID that was announced during build 2025. It wasn't much at that time. I think it was one column in some of the signing logs and filters. And then agent 365 was announced during Ignite 2025 in late 2025. Still very early days for both of these. Let's see what we can understand from these two capabilities. And perhaps reflect back on this topic in a future episode to see how these two have evolved. So before we dive deeper into what they saw, what the licensing model is and so on. Agendic engineering, web coding agents, a lot is happening. And yet I also feel things are measuring quite a bit in recent months. Toby, top of my thoughts on agendic engineering and gen AI right now. Yeah. I think great question. I think there's a lot of thoughts here. But perhaps let's boil it down to what I think matters to most right now for the shift in engineering globally. And honestly, for me, this kind of all distills down to one thing, which is agendic engineering becoming just engineering. Because everyone is talking about vibe coding and then everyone is talking about agendic engineering and then everyone is talking about the next cool thing or whatever new trend. But the matter of the fact is this is just engineering now. So we've kind of crossed the line where I think we can't imagine getting meaningful work done without agents in the loop. And that's a fundamental part of how work gets designed and executed today. So every pipeline you have, every workflow, every build, there's an agent in there somewhere. And you know, the vibe coding conversation is fun. We've had that a couple of times. I think it does undersell what's actually happening now as things mature. So I think that was your kind of keyword in the question as well. Things are mature. So this isn't about vibes or prototypes anymore because that's how it started. You could run up a prototype real quick. Now this is a, you know, what I see and for myself as well, this is a structural shift in how engineers operate the best engineers that I see right now. They're not just writing code. They're actually not writing a lot of code at all. They're orchestrating agents to do it with them. And that's a completely different skill set and mindset because it's not about taking pride in where you put the semicolon or what type of shape your code has or that you can optimize this or that line of code. That no longer matters. What does matter is understanding the expected outcome. So I think when people ask me, you know, what's top of mind like you just did, it's that. We're not heading towards a world where agents assist engineering. We're already in a world where engineering without agents is the exception or should be the exception. We did a measurement internally as we made some changes to our engineering organization, our engineering team. And by introducing the, you know, agentic approach, AI, agentic workflows and making sure we have the right tools at the right place with the right governance. We increased the outcome and an output capacity by 800 percent using the same staff. And that's pretty significant. That's eight times more deliverables using the same resources we have. So, you know, the other discussion, which we probably might need a full episode for is I also see a trend where organizations, what we thought initially is everyone is going to kick out engineers and consultants and, you know, everyone because we have agents. But that's not what I'm seeing now. What I'm seeing is, hey, we already have these resources in the team. How can we not optimize so we deliver the same with less people are now saying, how can we keep all these resources but deliver 10 times more, which is a shift from what people fear versus what I see happening right now. Which if that's any comfort, make sure you get on the agentic train, make sure you understand how to orchestrate these things because then you'll be a key resource in the time that comes ahead. I like this way of thinking and this reminds me somebody I know mentioned maybe a year ago that they did some wide coding. They knew nothing about Python. So they used perhaps GitHub co-pilot, built me something, a single prompt. It spits out something for you. You execute the Python, it does something. It's almost like magic. And when you hear about that for the first time, you go go like, well, okay, this is impressive but at the end of the day, your effort for this solution was maybe 10 seconds typing up the prompt. Then you get something out that you have no clue what's in there and it sort of works. If you then try to sort of sell the idea of the solution to somebody like me saying, here's my solution, I'm sure you'll appreciate this. I'm like, yeah, but this is AI Slop because I don't really grasp the idea why I should be interested in this one. I can replicate this in 10 seconds as well. I know I would still own the idea. But from those days, which was just maybe a year ago, to agentic engineering where you have teams of agents executing and producing code for you, not just solely on a single prompt but through a whole design. It's obviously a different thing.
thing. So this brings us now to agent 365. The core idea for agent 365 is it's a unified control plane for AI agents. And we could talk all about service principles and conditional access policies and governance in entri-d and Microsoft 365. But the idea obviously is sort of twofold. One, it's a technical control plane for managing your current and future AI agents with the anticipation that each and every organization will have hundreds and thousands of agents doing the work for you. That's one aspect. The second aspect is with the explosion of demand for agents, Microsoft probably sat down maybe a year ago, maybe two years ago and went, well hold on, we have this expected demand from customers to govern agents. We don't really have a solution for this. Let's build a commercial offering for this. Let's set a license price, let's package this into skews and let's roll it out. So when we are talking about agent 365, I feel you have to look at both angles on this one. The pure technical aspect, which is one and the sort of business ecosystem licensing aspect, which is another one. And I would say these are equal. But this gives you a visibility into which agents you have in your tenant or in your environments who owns them, what permissions and cons and then access they have and how they behave. That's essentially what agent 365 is. Joby, have you had a chance to play with agent 365 in any of your environments? It's been available since December 25, I'd say. Yeah, and that's also a great question. I don't I don't have any hands-on experience in my production environments. I do have access to an environment where we've taken a look at it. And it's kind of like what they describe on the documentation page as well. You know, they there's a registry, there's access control, there's officialization, interrupt, our ability and security. These are kind of the things they talk about. One thing that all of this boils down to for me when I take a look at it, when I've played around with it, it's agent 365 kind of gives you like each AI agent gets its own Microsoft agent ID. I know we talked about this in one episode as well. So you get an ID for identity lifecycle access management and that kind of allows agents to be observable and manage in the Microsoft 365 admin center. And you already have that. So it's not a new layer of governance because it's the same layer of governance that you all already have in use. It's just plugged in there. It's not something that I currently have rolled out in any production environment or into our kind of main estate. Mainly because you know, the organization I work with right now, we are a startup. And we don't need co-pilot in 365. We don't need any of the kind of Microsoft offerings in terms of agentic because we don't need it for our kind of work estate. It's not that big right now. We have a lot of agentic AI approaches in our workflows and engineering, but this is not it. This is I think this is more enterprise. This is more bigger organizations. Perhaps even small medium size if you use co-pilot, if you use the Microsoft 365 ecosystem a lot, we're a multi-cloud. So that's one thing that I think is good to keep in mind. This capability here stops at the boundaries of the Microsoft ecosystem. So if you are a multi-cloud, this gives you benefit on the Microsoft side of things. But as soon as you go into GCP, AWS, other type of clouds, you don't get the benefits from this, which is by design, of course, because most of these organizations live within the 365 ecosystem. So I think that's, you know, top of mind, my reflections on this is with the access control that you mentioned, you know, being able to observe and visualize things, what happens where, you know, what does the interoperability work look like? Because you have work, IQ integrations as well. And that means that, you know, whatever work you have and work files and things that are accessible can now, you know, be pulled in to the agent 365 and the agents you have. So it has context about the right things at the right place at the right times. I also took a look on the security aspect of this, of course, and agent 365 integrates with Microsoft Per View to apply, you know, your data protection policies and, you know, to be able to audit agent activity. And then you have Microsoft Defender to kind of detect and investigate and respond as, you know, the pitch goes to any threats coming from these things as well. So there's a lot of things in the documentation. I don't want to just go through whatever the documentation says because you can do that yourself. But those are the kind of initial reflections I've taken a look at. It does look like Microsoft has spent a lot of time figuring out that this is not a new app that you put on top. This is kind of integrated into the existing tools you have. Yeah, exactly that one. And for me, agent 365 is a little bit vague in the beginning. So what it now includes by the time it's generally available, which is May 1, 2026, it's going to be including registry for having a complete view on all the agents. Access control, obviously, true, entra visualization, which I feel is less of less useful, I would say. It's fun, but it's not really working out that well for me so far. Interoperability, meaning that what are the agents actually doing and security integrating to Pervy and the other aspects you said, for interoperability, I'm thinking if you are outside the Microsoft ecosystem, let's say you're building an agent on Salesforce or ServiceNow or Google or something else, you would have the option of surfacing your agent to agent 365 through the A365 tooling and the SDK. I'm not sure if there's a sort of a commercial driver for that, unless obviously if you want your agent to surf us on any future market places, that Microsoft invested businesses would be in. So it's going to be interesting to see how this plays out. So moving on from agent 365 to entra agent ID, this is the identity layer underneath agent 365. And I would say the difference between the two is that agent 365 is for Microsoft 365 admins and IT pros to govern and orchestrate agents that are already there. An entra agent ID is the identity layer for developers, IT pros, admins looking after identities in understanding how do we want to configure identity based access for agents that are built with Foundry, GoPilot Studio, TrueCodePilot and so on. And the key thing here for entra agent ID is conditional access support for agents. And you could argue that well, ServicePrincipals sort of had that support already, but it would be very confusing to see ServicePrincipals being only governed to CA policies when in reality you're talking about agents. And entra agent ID that's surfaced through the entroportal right now. And I'd say it's a little bit more contained functionality because you can see everything in one view while agent 365 sort of sprawls across multiple different platforms and environment in that sense. Toby on entra agent ID and I know you've been working with entra for ages. This sort of touches on zero trust and authentication and authorization and consent and everything else. Thoughts on this one, how do you see this play out? Yeah, I think this is it's kind of what you said in the beginning, right? If agent 365 is kind of the platform, then entra agent ID is the identity engine underneath it. So entra agent ID is kind of part of the Microsoft agent 365 ecosystem. What I think here is like for years, we talked about zero trust as a people and device problem and always people and device. You verify the user, you verify the device, you grant access accordingly. But agents kind of break that model completely if you think about it. And agent is not a person. It does not log in with an MFA prompt. It can be created and destroyed in a couple of seconds. And yet, you know, this might be accessing your most sensitive data or SharePoint libraries, whatever it is, sending emails on someone's behalf or making decisions inside a business process that you may or not may not be aware of. These are kind of things we're talking about now. So giving agents their own identities with entra agent ID
you know, real, governed, auditable identities, just like any individual, that to me is the thing that makes everything here possible. Because without that identity, you have now accountability. If it runs as your user, well guess what? You're accountable for whatever happens. So this is one of the discussions I've had both internally and with customers worldwide. A lot of folks say, well, and I read on X or Twitter, I read on LinkedIn, I see these stories about someone saying, my agent deleted all my files in production or the database in production. No, actually you did. Like the agent is just an extension of your arm and your permissions. And if you're running with your admin account in Azure and allowing your agent to execute any command on your behalf in the terminal, well guess what? Anything can happen and you're accountable for that because you made that happen. It's not like the agent just created itself and used your permission and did it. Of course there's malicious agents. That's something we can talk about in a different episode as well. But most of the mistakes I see today is because people grant them too much control. Or saying, hey, whatever happened, I'm just gonna use an agent here to get something done and you use your own permissions. And when you do that, well guess what? If you're a global admin in Azure, it has full control to everything and it can do whatever you can do. And that's not the agent's fault, that's your fault. You need to connect it to a specific identity and restricts access, monitor and govern that. So, because without that identity, you have no accountability and without accountability, you have no governance and without governance, you're just hoping your AI agents behave. So what I appreciate here is that Microsoft did not try to kind of re-event the wheel again. Kind of what I mentioned that everything already exists in the tools. They took the kind of entry framework and platform that your team already knows, right? We're already using this conditional access, identity protection, lifecycle management, and just extended that to agents. So instead of kind of learning a whole new security model for AI, you're applying the one that you've already invested in to the identities of AI. And this is what I think is really clever, where it's not, okay, now you have 90 agents running here and then you have to go and govern and figure out all these things. Now there's native tools already on the Microsoft platform and the ecosystem to handle this. And that's what I like about this specific approach. I'm still thinking on agents and the sort of aspect on this one. I'm not sure too many companies are fully prepared what this will eventually entail. And I'm predicting there's going to be a lot of shadow IT in the sense that people spin up stuff because they want to try something out there, red on the internet. That's one we've seen that we open a clone now, for example. But the second aspect is that businesses went sort of all in with Microsoft 365 Copilot to see where the productivity gains would be. And now after a couple of years, agents seem to be doing the same thing, but that obviously requires people to have the mindset of of loading the work to agents at the same time. Briefly on cost, agent 365 standard analysis is $15 per user per month. Considering that Office 365 E3 is roughly the same price, I'd say agent 365 is definitely not in the low end in terms of cost, but it's going to be giving you a lot of their boundaries for managing agents. And on top of this, Microsoft 365 E7 suite is $99 per user per month. So this bundles together the E5 license, including Office and the security capability is Microsoft 365 apps and so on. Microsoft 365 Copilot enters suite including global secure access and agent 365. One question that I've been sort of choying with while sitting in the traffic lights is that who do we need to buy the E7 license for? For me, it's not going to be ID admins. They typically do that need Microsoft 365 Copilot as an example. End users probably make sense, but that would entail that we expect all users to somehow be exposed to agents. External's probably not because they might not need interest suite unless you go for GSA for externals, they might not need Copilot. So again, you sort of do a mixture of licenses. E5 for majority of users, maybe E3 for those without a physical device, and then E7 or E5 plus agent 365. For everybody who gets exposed to agent 365. So it's going to be an interesting aspect in manipulating the license model to feed the organization. And probably a good idea to start considering who will benefit from agent 365 licensing and that will eventually drive the license models. But to sort of recap this, agent's role is definitely something we can expect to happen. And we're sort of seeing the first steps for that right now. The shadow item, the sense that people are spinning up stuff, people might be using GitHub Copilot that they have a license for to work, but then they would be executing a lot of things in there. That's one aspect. And perhaps more prominently is the known human identities, meaning entra agent IDs are being treated as a first class identity alongside human identities. Anything else Toby, you would highlight from here for anybody considering agent 365 or E7 alongside with entra agent ID in the next couple of months. - I know one thing, and I haven't checked up on the latest data this, but like you mentioned, the Microsoft 365 E7 Frontier suit. One thing that I know they announced in December last year is that you should get into the frontier program if you can, 'cause agent ID is available using agent 365 early access in Frontier. I don't know what happened to that, but that's worth checking out as well. If that program exists still, not just early addition, and if you're eligible to jump into that, that might be worth checking in or checking out, depending on how you see it. So I think that's important. The other thing that we discussed is sign an owner to every agent, right? This is one thing I learned about all the different agents that we have in all the different platforms and whatever we operate, a sign an owner to the agent. So with agent identities, you can govern and manage the identity and access lifecycle of the agents like we discussed. And you can ensure that the agents have a responsible person providing oversight throughout the agent lifecycle. 'Cause guess what, if you have 900 agents across a large enterprise or a large organization, and this is just gonna keep growing, who do you reach out to? Who's accountable for this? This is an ungoverned or a shadow agent popping up. This is something with too much permissions or this thing is doing something it's not supposed to. Who do you reach out to? So that's more like the enterprise problem of assigning ownership. And orphaned agent IDs with stale permissions. I think that's the real risk. Someone spun up an agent to get one off work done. And guess what, now it's still there with whatever permissions. It's got, it's stale permissions in the sense that it still has whatever permission it has. Nobody knows who created it or nobody knows what this agent is doing or why it's there. And what can you do? Can you still do stuff? Can you access stuff? It's not supposed to. How does that fit in with your compliance GDPR Cloud Act, ISO 27,001, talk to type 2, whatever? How does that map into your compliance standards if you have agents now with access to things they're not supposed to have access to? Because part of the regulatory compliance frameworks only trained and authorized staff are allowed to have access to certain resources, including cloud infrastructure, data layers, and all these things. So if you now have agents operating as your identity, guess what, you're breaking compliance. If you now have agents operating under their own identities but they have access to these resources, guess what, you're also risking compliance breach. So I have a lot of reflections on this because it's not just a technical problem, which button do I click to get this? 'Cause that's the easy part. You can buy a license and then you have it, voila. Great. How do you govern this at scale? How do you make sure in an enterprise that we're doing the right thing and that we govern, monitor, and restrict whatever is necessary, both short and long term? So a lot of reflections on this, but that set, you know, do take a look at this. If you live within the Microsoft 365 ecosystem, if everything you do is in the Microsoft text space, this is for you. This is something to definitely take a look at and see how it can help you out. And I also just saw
Sachin and Adela make some LinkedIn posts with a couple of new co-pilot and N365 capability. So they just keep rolling things out and the more of these things I see, the more I see the need for this as well. Well said. To sort of sum it up, Agent Trisha's to five is the platform and Entry Genoaidi is the identity backbone. They work together. So for the next couple of months, definitely have a look at those capabilities prepare that at some point you're going to be needing Agent Trisha five and by proxy that brings in Agent ID as well for you. Alright, have a look at the show notes. We have some links for additional resources on these topics. Thanks again for tuning in. See you next week. Alright, see you then. [Music]
Podcast Summary
Key Points:
The hosts discuss their recent experiences
The main topic is Microsoft Agent 365 and Entra Agent ID, both announced in 2025, focusing on governance and identity for AI agents.
Agentic engineering is now mainstream, shifting from writing code to orchestrating agents, with some teams achieving an 800% increase in output using the same staff.
Agent 365 is a unified control plane for managing, governing, and securing AI agents across Microsoft 365, integrating existing tools like Microsoft Purview and Defender.
Entra Agent ID provides identity management for agents, enabling zero-trust principles, conditional access, and accountability, preventing agents from running with excessive user permissions.
Agent 365 standard license is priced at $15 per user per month, with availability from May 1, 2026.
Summary:
In this episode of Control Alt Azure, Tobias and UC discuss the rise of agentic engineering and Microsoft's new offerings: Agent 365 and Entra Agent ID. UC shares his experience from the Microsoft MVP Summit in Seattle, noting the challenges of jet lag and the difficulty of meeting everyone due to the event's distributed locations. Tobias contrasts this with the arrival of spring in Sweden, which lifts his mood.
The core discussion centers on how agentic engineering has evolved from "vibe coding" prototypes to a structural shift where engineers orchestrate agents rather than write code manually. UC highlights that his team achieved an 800% increase in output by adopting agentic workflows, emphasizing that agents are now integral to engineering, not just assistants. Agent 365 is described as a unified control plane for managing AI agents within the Microsoft ecosystem, offering registry, access control, interoperability, and security integrations with Purview and Defender.
It is designed for IT pros to govern agents at scale, though it is limited to Microsoft environments. Entra Agent ID serves as the identity layer beneath, giving agents their own identities for zero-trust governance, conditional access, and accountability. This prevents agents from using user permissions and causing unintended damage.
The hosts note that many organizations are unprepared for the shadow IT risks of agent proliferation, and that the $15 per user per month licensing cost for Agent 365 standard will be a key consideration. Overall, they view these tools as a natural extension of existing Microsoft security and management frameworks, rather than a completely new approach.
FAQs
The episode focuses on Microsoft Agent 365 and Entra Agent ID, discussing their capabilities, licensing, and governance for AI agents.
Agent 365 is a unified control plane for managing and governing AI agents within the Microsoft ecosystem, providing visibility, access control, and security.
Entra Agent ID is the identity layer for agents, enabling identity-based access control and conditional access, while Agent 365 is a broader management platform for IT pros.
It ensures accountability, governance, and auditability, preventing agents from running under a user's permissions and causing unintended actions.
It integrates with Microsoft Purview for data protection, Defender for threat detection, and the Microsoft 365 admin center for management, using existing governance frameworks.
Agent 365 standard is priced at $15 per user per month.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.