> ## Content Index
> Fetch the complete content index at: https://blog.aperion.ai/llms.txt
> Use this file to discover other available public pages before exploring further.

# Microsoft Copilot Agent Governance: Copilot Studio, Foundry and Agent 365
- URL: https://blog.aperion.ai/microsoft-copilot-agent-governance-guide/
- Published: 2026-10-06T21:41:42.000Z
- Updated: 2026-10-06T21:41:42.000Z
- Description: Agent 365, Entra Agent ID, Purview and Defender each cover part of governing Microsoft agents. How they fit together, and the gaps to close, in seven steps.
- Author: Craig Alberino
- Tags: Guides, AI Agents, AI Governance

*Updated October 6, 2026\. Part 6 of APERION's Agent Platforms series.*

**Microsoft governs agents through four products working together: Agent 365 as the registry and control point, Entra Agent ID for agent identity and Conditional Access, Purview for audit and data loss prevention, and Defender for threat detection.** Copilot Studio and Microsoft Foundry add their own data policies, guardrails and tracing. To govern Microsoft agents, register every agent in Agent 365, give each one an Entra agent identity with a human sponsor, put Copilot Studio's connectors and MCP servers under data policies, add Defender block rules once you have reviewed its audit results, and export Purview audit records before retention ends.

Microsoft made Agent 365 generally available on May 1, 2026, at $15 per user per month or as part of Microsoft 365 E7 ([Microsoft, May 2026](https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/)). Two months later, Microsoft reported nearly 40 million agents registered across tens of thousands of companies, and more than 30 million paid Microsoft 365 Copilot seats ([Microsoft earnings call, July 2026](https://www.microsoft.com/en-us/investor/events/fy-2026/earnings-fy-2026-q4)).

## What Microsoft Ships for Governance

| Product           | What it does for agents                                                                                                    | Status and licensing to check                                                                           |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| Agent 365         | Registry, lifecycle rules, policy templates, tool access control, and blocking of unsanctioned local agents through Intune | Several capabilities require E7 or the standalone license                                               |
| Entra Agent ID    | Agent identities with blueprints and human sponsors; Conditional Access and access packages for agents                     | Extending Entra security features to agents requires Agent 365                                          |
| Purview           | Audit, data loss prevention, eDiscovery and retention for Copilot and agent interactions                                   | Audit records carry metadata; DLP for prompts is in preview                                             |
| Defender          | Threat detection for agents, and real-time protection that can block tool invocations                                      | Real-time protection is generally available for Agent 365 and in preview for Copilot Studio and Foundry |
| Copilot Studio    | Power Platform data policies on connectors and MCP servers; an external threat detection hook before each tool call        | The external hook is in preview                                                                         |
| Microsoft Foundry | Guardrails at user input, tool call, tool response and output; AI gateway on API Management; OpenTelemetry tracing         | Tool call and tool response guardrails are in preview                                                   |

Sources: Microsoft Learn for [Agent 365](https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-agent-365/microsoft-agent-365), [Entra Agent ID](https://learn.microsoft.com/en-us/entra/agent-id/identity-platform/what-is-agent-id-platform), [Purview for Agent 365](https://learn.microsoft.com/en-us/purview/ai-agent-365), [Defender real-time protection](https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-real-time-protection), [Foundry guardrails](https://learn.microsoft.com/en-us/azure/foundry/guardrails/guardrails-overview) and [Foundry AI gateway](https://learn.microsoft.com/en-us/azure/foundry/configuration/enable-ai-api-management-gateway-portal), verified October 6, 2026.

## Where the Control Points Are in Microsoft's Stack

**Microsoft 365 Copilot runs inside Microsoft's service boundary.** Microsoft states that prompts, retrieved data and responses remain within the Microsoft 365 service boundary ([Microsoft Learn](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy)), and that Copilot integrations can fail when TLS inspection interferes with the connection ([Microsoft Learn](https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-requirements)). Microsoft documents no customer proxy for its model calls. Govern it with Purview, Agent 365 and the admin center's tool controls.

**Copilot Studio uses Microsoft-managed models.** Makers choose from Microsoft's list, which includes OpenAI and Anthropic models, subject to admin settings. Bring-your-own-model applies to prompts through Foundry models, and does not replace the agent's orchestration model ([Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-copilot-studio/bring-your-own-model-prompts)).

**Tool calls are where customers can act.** Copilot Studio connects MCP servers through Power Platform connectors, so they fall under data policies ([Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-copilot-studio/mcp-add-existing-server-to-agent)). Admins can block MCP servers and connectors in the Microsoft 365 admin center, and approve bring-your-own MCP servers, in preview ([Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-byo-mcp-server)).

**Code-first agents choose their endpoints.** Agents built with Microsoft Agent Framework, the successor to Semantic Kernel and AutoGen, run in your code and call the model and tool endpoints you configure ([Microsoft Learn](https://learn.microsoft.com/en-us/agent-framework/overview/agent-framework-overview)).

## How to Govern Microsoft AI Agents in 7 Steps

### 1\. Register every agent in Agent 365

Use the Agent 365 registry as the Microsoft-side inventory, sync Foundry agents into it, and block unsanctioned local agents through Intune where your license allows. Reconcile it with agents on other platforms.

### 2\. Give every agent an Entra identity and a sponsor

New Copilot Studio agents receive Entra agent identities automatically; agents created before May 2026 keep their app registrations. Name a sponsor for each, the person accountable for its lifecycle and access. When an agent acts on a user's behalf, Entra records the user as the subject and the agent as the actor ([Microsoft Learn](https://learn.microsoft.com/entra/agent-id/agent-identities)).

### 3\. Apply Conditional Access to agents, and close the API-key gap

Write Conditional Access policies that target agents and blueprints. Microsoft states that an agent authenticating with an API key "bypasses the Microsoft Entra ID authentication and token issuance pipeline entirely and Conditional Access policies won't apply" ([Microsoft Learn](https://learn.microsoft.com/en-us/entra/identity/conditional-access/agent-id)). Inventory API-key authentication and replace it where you can.

### 4\. Put connectors and MCP servers under data policies

Classify connectors and MCP servers in Power Platform data policies, block the ones agents should not use, and filter HTTP calls by endpoint. Microsoft no longer supports exempting agents from data policy enforcement ([Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-copilot-studio/admin-data-loss-prevention)).

### 5\. Make tool-call checks fail closed

Copilot Studio's external threat detection, in preview, sends each proposed tool call to Defender or another provider before it runs. If no decision arrives within one second, the agent proceeds by default; change its error behavior to block when your agents take consequential actions ([Microsoft Learn](https://learn.microsoft.com/en-us/microsoft-copilot-studio/external-security-provider)). Defender's built-in real-time protection rule audits only; add custom block rules once you have reviewed the audit results.

### 6\. Turn on Foundry guardrails at every intervention point

For Foundry agents, apply guardrails at user input, tool call, tool response and output. Microsoft documents that agent guardrails fully override model guardrails, so set them at the agent level deliberately.

### 7\. Export the audit record

Purview audit records for Copilot and agents carry metadata such as resources, labels, model and jailbreak flags ([Microsoft Learn](https://learn.microsoft.com/en-us/purview/audit-copilot)); Microsoft surfaces prompt and response text through Purview DSPM for AI and eDiscovery. Copilot Studio and Foundry fall under Audit Standard with 180-day retention. Export records to your SIEM, and keep content where your obligations require it.

## What EchoLeak Showed

EchoLeak ([CVE-2025-32711](https://nvd.nist.gov/vuln/detail/CVE-2025-32711)), published in June 2025 and rated 9.3 by Microsoft, let an attacker send an email that Microsoft 365 Copilot later read as context and used to send internal data out, with no click by the user ([arXiv, September 2025](https://arxiv.org/abs/2509.10540)). Microsoft fixed it on the service side. Earlier, a server-side request forgery flaw in Copilot Studio exposed internal Microsoft infrastructure tokens and was addressed in August 2024 ([CVE-2024-38206](https://nvd.nist.gov/vuln/detail/CVE-2024-38206)). Both were fixed by Microsoft. The customer's part is limiting what agents can read and where they can send it.

## Operating Limits

- **Microsoft 365 Copilot processes within Microsoft's service boundary.** Microsoft documents no customer proxy point.
- **Conditional Access does not apply to API-key authentication.**
- **Purview audit records center on metadata.** Decide where prompt and response text is kept and reviewed.
- **The external threat detection hook proceeds after one second by default.** Configure fail-closed.
- **Purview DLP cannot scan files uploaded directly into prompts.**

## How APERION Fits

APERION's Smartflow composes with Agent 365 and Entra. It validates the Entra ID tokens your tenant already issues, and its MCP gateway can front the MCP servers Copilot Studio agents connect to, applying tool rules and sending out-of-authority calls to a person with approval rights. For code-first agents built on Agent Framework or Foundry, it can serve as the model endpoint. Every call lands in one hash-chained record alongside your non-Microsoft agents. [Talk to APERION](https://aperion.ai/contact).

## More in This Series

- [How to govern AI agents across platforms](https://aperion.ai/blog/govern-ai-agents-across-platforms-guide/)
- [CrewAI security and governance](https://aperion.ai/blog/crewai-security-governance-guide/)
- [Glean agents governance](https://aperion.ai/blog/glean-agents-governance-guide/)
- [Agentforce governance](https://aperion.ai/blog/agentforce-governance-guide/)
- [Amazon Bedrock AgentCore governance](https://aperion.ai/blog/aws-bedrock-agentcore-governance-guide/)
- [Google, ServiceNow, OpenAI, Anthropic and LangChain](https://aperion.ai/blog/google-servicenow-openai-anthropic-agent-governance-guide/)

## Frequently Asked Questions

### What is Microsoft Agent 365?

Agent 365 is Microsoft's control point for AI agents, generally available since May 1, 2026\. It provides an agent registry, lifecycle rules, policy templates and tool access control, and extends Entra, Purview, Defender and Intune protections to agents.

### What is Microsoft Entra Agent ID?

Entra Agent ID gives each agent its own identity, created from a blueprint and assigned a human sponsor. Agents can then be covered by Conditional Access, access packages and identity governance. Microsoft states that extending Entra security features to agents requires Agent 365.

### Can I route Microsoft 365 Copilot through my own gateway?

Microsoft documents no way to do so. Copilot's processing stays within the Microsoft 365 service boundary, and Copilot integrations can fail when TLS inspection interferes with the connection. Govern it with Purview, Agent 365 and admin center tool controls.

### Does Copilot Studio support MCP?

Yes. MCP has been generally available in Copilot Studio since May 2025, over streamable HTTP, with MCP servers connected through Power Platform connectors that fall under data policies.

### Do Purview audit logs capture Copilot prompts?

Purview audit records for Copilot and agent interactions carry metadata such as the resources accessed, sensitivity labels, the model and detection flags. Prompt and response text is reviewed through Purview DSPM for AI and eDiscovery.

### Does Conditional Access apply to AI agents?

Yes, for agents that authenticate through Entra tokens, including on-behalf-of, app-only and agent user flows. It does not apply when an agent authenticates with an API key.

### What was EchoLeak?

EchoLeak, CVE-2025-32711, was a zero-click vulnerability in Microsoft 365 Copilot published in June 2025, in which an attacker's email led Copilot to disclose internal data. Microsoft fixed it on the service side.

---

*Craig Alberino is the CEO and Founder of [APERION](https://aperion.ai), which provides Smartflow, the runtime governance layer for enterprise AI in regulated industries. [Learn more about Smartflow →](https://aperion.ai/products/smartflow)*