Microsoft adds network controls for Copilot Studio agents

Microsoft has made Agent 365 generally available. The service extends Entra network controls to agents built in Copilot Studio and endpoint agents including OpenClaw. It adds discovery for local and cloud agents via Defender and Intune. Registry sync for AWS Bedrock and Google Cloud is in preview. A preview for Windows 365 for Agents is available in the US.
Until recently, fears over data leaks and unmonitored agent activity kept adoption of custom agents low even in companies that paid for Copilot. Teams often avoided the feature entirely to stay compliant. Agent 365 now brings these agents under Entra and Defender oversight for traffic inspection and attack prevention. The mid-2026 timeline for asset context mapping however leaves organisations with partial visibility in the meantime.
Analysis
Most coverage will call this a breakthrough for safe AI agents. In reality it means you now have to navigate additional security layers to use them. Check the agent discovery section in Microsoft Defender this week to see the current state of play.
Citation
This executive briefing was curated and analyzed by Collab365. To reference this analysis, please attribute: "This briefing is available on Collab365 Spaces (spaces.collab365.com)".