Microsoft Agent 365 GA: $15/Month to Govern Every AI Agent in Your Enterprise
Microsoft Agent 365 is generally available as of May 1, 2026. It is the first enterprise product explicitly designed to govern AI agents rather than human users — a centralised registry and security layer for every AI agent running across an organisation’s Microsoft 365 and multicloud footprint.
Pricing: $15/user/month as a standalone add-on, or bundled into the new Microsoft 365 E7 “Frontier Suite” at $99/month. E7 is a new license tier that sits above E5.
What the Problem Is
Microsoft calls it “corporate double agents.” As organisations deploy hundreds of AI agents built on Copilot, OpenAI, Anthropic, and third-party platforms, those agents accumulate access, permissions, and data connections that no team is actively monitoring. An agent authorised to read calendar data may retain that access indefinitely; an agent that was provisioned for a test workflow may never be deprovisioned.
Agent 365 addresses this with a centralised agent registry — analogous to an identity directory for non-human entities — combined with OpenTelemetry-based logging of agent actions and interactions. Every agent, regardless of whether it was built on Copilot or imported from a third party, appears in the registry with its permissions, data scopes, and activity history.
Security Integration
The product extends three existing Microsoft security layers to agents:
- Microsoft Entra: identity and access management for agents as principals
- Microsoft Purview: data governance and compliance visibility across agent interactions
- Microsoft Defender: threat detection for agent-related anomalies, including compromised agents and prompt injection vectors
This is significant. Prompt injection — where an attacker embeds instructions in content that an agent reads, causing it to act outside its intended scope — is the dominant agent security risk class. Routing agent activity through Defender’s detection infrastructure gives enterprise security teams visibility they currently lack.
Copilot Cowork
Shipping alongside Agent 365 is Copilot Cowork, a product built in collaboration with Anthropic. Cowork enables multi-agent workflows within the Microsoft 365 environment, with structured handoffs between specialist agents. Microsoft has not disclosed which Anthropic models power the product, but the announcement confirms the first public Anthropic integration at the Microsoft 365 layer — distinct from the Azure OpenAI relationship.
Context
Microsoft has been signalling this direction since Ignite 2025. The May 1 GA arrives eight months later, after enterprises spent the intervening period deploying agents without the governance layer. Agent 365 is a bet that organisations now have enough agent sprawl to pay $15/seat/month for observability.
The product also implicitly prices out the alternative: building custom monitoring infrastructure for agent fleets is a multi-sprint engineering project. At $15/user/month for an organisation with 1,000 enterprise users, the buy-versus-build math clears the hurdle quickly.
The new E7 Frontier Suite at $99/month bundles Agent 365 with the existing E5 stack. For organisations already near E5 pricing, the incremental cost for the full agent governance layer is in the low single digits per user per month.