Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Local agents are becoming everyday tools. AI coding assistants and other developer tools now run directly on laptops and workstations, doing real work in the user's own environment. That closeness to where work happens is what makes them powerful, and what makes them hard to see. Agent 365 treats an agent running on a device as something an enterprise governs, not something it finds out about later.
What makes a local agent different
A cloud agent is created, authenticated, and monitored inside systems the enterprise already controls. A local agent runs on the device itself, so it can be installed in minutes, act with the user's own local access, and begin reaching files, credentials, source code, and internal systems before a security team knows it exists. Agent 365 represents each one as an agent identity tied to the user, the device, and the type of agent it is, which is what makes an agent on a laptop governable the same way as one in the cloud.
Local agents take many forms: command-line tools, desktop applications, agentic development environments, code editor extensions, and local agent frameworks. What they share is proximity to the work. An agent that can access a source code repository, run commands, and call internal services is far more useful than one confined to a web app, and it is a far larger security risk surface to account for.
Where it runs changes the risk
A local coding agent often holds access keys and passwords for the code and cloud systems it works with, so a single compromised device can expose far more than one machine. The same agent also carries different risk depending on where it runs: on a compliant, managed device it is one thing; on a compromised device it is another. Because Agent 365 ties each local agent identity to the device it runs on, that difference is something an administrator can see and act on rather than assume.
Seeing what runs on the device
Because local agents live on the device, the first requirement is knowing they are there. Agent 365 brings local agents into a single inventory in the Microsoft 365 admin center, so an administrator can see which agents are running, how widely they have spread across the organization's devices, and which are still active.
That inventory is what makes a decision possible. Once an administrator can see a local agent, they can judge it on the terms that matter on a device: the security posture of the machine it runs on, rather than the agent in isolation.
Wider coverage and safer defaults
An inventory is the starting point. From there, the direction for Agent 365 is broader coverage across more devices and stronger control over how a local agent runs. One emerging approach is to run the agent inside an isolated container: a separated space on the device where the agent can do its work while its reach into the rest of the machine, its files, and the network stays limited. Containment keeps the productivity of a local agent while limiting the damage a single compromised agent or device can do.
Local agents deliver real productivity, especially for developers. The goal is not to remove them. By giving an agent on a laptop an identity and a place in the same inventory, Agent 365 lets an enterprise hold what runs on the device to the standard it already sets everywhere else, instead of governing only the half it can see.