Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
An enterprise running hundreds of agents will always have a few that are its most urgent security problems: exercising more access than their job needs, behaving in ways that look like a compromise, or being targeted by attacks. Leaders can't watch every agent themselves. Volume is only half of it. Risk is also uneven, and which agents carry it changes as their permissions, tools, and behavior change. Agent 365 surfaces risk signals for each registered agent so an administrator can see where exposure stands now rather than inferring it from what an agent was approved to do.
Two things make that workable. The signals come from the security services the enterprise already runs, not from a separate, agent-only security model. And because each agent carries its own identity, a finding is never an anonymous alert; it names an agent someone can act on.
What risk signals show
Knowing an agent exists is not the same as knowing whether it is dangerous. A risk signal is a specific, high-severity finding about one agent: that its access exceeds its declared function, that it is behaving in an unusual or suspicious way, that an attempted prompt injection, where hidden instructions in content try to hijack the agent, was caught while it was running, or that sensitive data was reached in a way that looks like it is being stolen.
Each signal carries a severity and a confidence level, so an administrator can tell a serious, well-evidenced finding from a weak one. The aim is not to log every anomaly; it is to surface the exposures that genuinely warrant a response.
One view of exposure
Consolidation is what makes those signals usable. They come from Microsoft Entra for identity, Microsoft Purview for the data an agent can reach, and Microsoft Defender for its behavior while running, and they arrive in the Microsoft 365 admin center as one view that refreshes on a regular cadence rather than at review time.
From flagged to handled
A finding only helps if it leads somewhere. Each signal points to the control that resolves it, and because the flagged agent is already a named identity and not an anonymous alert, that control can be applied directly. An administrator can limit the access of an agent that has more than it needs, block a clearly risky one outright, or hand an active threat to the security team for investigation in Microsoft Defender. Triage starts here; deeper investigation and remediation continue in the security tools the enterprise already runs.
The direction is to fold more security signals into the same view, so more of what could make an agent dangerous surfaces in one place rather than in a separate console someone has to remember to check.
Several questions sit deliberately outside this set and need their own treatment: how an agent identity is created and retired, finer-grained authorization beyond blocking, the audit trail, the handoff into security operations, and the risks agents create for one another and through the tools they share.
Agent 365 turns the constant activity of many agents into something leaders can actually oversee: not a longer list of alerts, but a short list of agents that need a decision, each one named and each one attached to the control that settles it. Across identity, discovery, tools, templates, and risk, the through line holds. An enterprise can give agents real capability and still answer, at any moment, which of them to worry about.