Insights View Recording: Agent 365: Governing the Workforce You Didn’t Hire

View Recording: Agent 365: Governing the Workforce You Didn’t Hire

Agent 365: Governing the Workforce You Didn’t Hire

Agents are arriving inside M365 whether or not there’s a plan for them. This session lays out Concurrency’s point of view on what organizations should be doing right now—from a licensing, governance, and management standpoint—to bring agents into the modern work fabric deliberately instead of by accident. We’ll cover how Agent 365 reshapes governance, where licensing decisions have the biggest impact, and the operating model that keeps agent adoption from outrunning your controls.


We’re also excited to welcome special guest Drew Johnson from Microsoft, who will share insights into the evolving Microsoft AI ecosystem and what organizations should be considering as agents become an increasingly important part of everyday work.

If you’re responsible for AI strategy, governance, licensing, or adoption, this is a session you won’t want to miss. Join Concurrency and Microsoft to understand what’s changing, what actions are worth taking now, and how to position your organization for successful agent adoption before the next wave of AI innovation arrives.



As AI agents move from “interesting pilots” into the core of how work gets done, most organizations hit the same wall: it’s no longer a question of whether you can build agents — it’s whether you can manage them confidently and securely at scale. Agents are being created everywhere — by pro-code developers, by AI-savvy knowledge workers in tools like Copilot Studio, and by employees adopting agents off the web that IT never sees. Analysts project more than 1.3 billion agents in operation by 2028. That shift is not a distant scenario; it’s a near-term reality IT leaders need to prepare for now.

The problem isn’t a single problem — it’s agent sprawl that compounds across three surfaces at once: SaaS agents adopted through the browser (the next evolution of shadow IT), endpoint agents installed directly on laptops and phones with deep access to local files and credentials, and cloud agents wired into APIs, MCP servers, and data stores across multi-cloud environments. These surfaces don’t just add risk — they multiply it, because agents interact across boundaries that traditional security models were never designed for. Left unmanaged, adoption turns into duplicate agents, ownerless agents, unmanaged access, and operational risk that quietly threatens the productivity gains agents were supposed to deliver.

In this webinar, we break down a practical, IT-first way to bring agents under control — treating them with the same rigor you already apply to users, apps, and devices. Instead of theory, you’ll see how Microsoft Agent 365 acts as a control plane for agents, and how to move from scattered experimentation to a governed, repeatable rollout across the enterprise.

Ben Lockwood (Concurrency) and Drew Johnson (Microsoft) walk through the three core capability areas every agent program needs — Observe, Govern, and Secure — and why you can’t control what you can’t see. Through a live demo of Agent 365, they show how every agent is onboarded into a registry with a unique ID (just like a user or device), how to spot and block agents flagged “at risk,” how to assign owners to ownerless agents and automate that with rules, and how a visual connection map reveals which agents are talking to each other. They also cover the distinction between agent proliferation and agent sprawl, why Agent 365 works with any agent (not just those built on Microsoft platforms), and how licensing actually works through the new E7 Frontier Suite.

WHAT YOU’LL LEARN

A practical way to decide how to govern agents at scale — starting with visibility and control, not more experimentation. How to move from agent pilots to a governed, repeatable rollout, and why agents need to be managed with the same rigor as users, apps, and devices.

The three surfaces where agent sprawl compounds (and the risk each one carries):

  1. SaaS agents — employees discovering and adopting web-based agents without IT’s knowledge (shadow IT/Shadow AI), and the sensitive information being shared with them.
  2. Endpoint agents — agents installed on laptops, desktops, and mobile with deep access to local files, credentials, and system resources, where an over-permissioned agent becomes a new attack vector on the device.
  3. Cloud agents — the deepest-integrated agents connecting to APIs, MCP servers, data stores, and other agents, where a single misconfiguration can become an entry point into your broader infrastructure.

The three core capability areas of Agent 365 (and what each one really means):

  • Observe — get the full picture of every agent in your organization, its usage patterns and behaviors, so you can answer the question most orgs still can’t: what agents exist, and who is using them?
  • Govern — extend IT’s existing policy-driven governance to agents: control who can create and onboard them, enforce guardrails, manage lifecycle, and stay audit-ready — governance that enables scale instead of blocking it.
  • Secure — protect agent identities and access, safeguard the data agents touch, and defend against an expanded threat landscape that now includes agent-to-agent, agent-to-tool, and agent-to-app interactions, identity and privilege abuse, and tool misuse.

How the demo makes it concrete. You’ll see the agent registry and unique agent IDs, an “Agent at Risk” alert and one-click block, assigning owners to ownerless agents, automation rules (e.g., reassigning ownerless agents to a manager), agent lifecycle cleanup for unused agents, the visual connection map of agent dependencies, per-agent performance stats, Shadow AI detection, and conditional access policies applied to agents just like users.

Why Agent 365 works with any agent — not just Microsoft-built ones. How the Agent 365 SDK — included in Microsoft’s Agent Framework — brings a broad ecosystem of ISVs, AI platforms, and enterprise SaaS agents into one unified, governed foundation, and why the more of your existing Microsoft tools you connect, the greater your visibility.

How licensing actually works. Where Agent 365 fits in the new E7 Frontier Suite (Entra Suite + Microsoft 365 Copilot + Agent 365), the E5 prerequisite, the standalone per-user option, and why the license is assigned to the user who builds and manages agents — not to the agents themselves.

Where to start. How to bring agents under control by managing them like users — extending the infrastructure and protections you already have across a distributed control plane — for faster time to value, lower operational risk, and the confidence to scale AI as a standard capability.

FREQUENTLY ASKED QUESTIONS

Is this webinar a product demo or a strategy session?

Both. The session frames the “why” behind governing agents at scale, then includes a live click-through demo of Agent 365 in the admin center — the registry, at-risk agents, ownership and rules, the connection map, and Shadow AI detection.

Who should attend?

IT and security leaders, admins, and technology decision-makers who are scaling agents and need visibility, governance, and protection — anyone responsible for keeping the environment secure as agents proliferate.

What is “agent sprawl,” and how is it different from agent proliferation?

Proliferation is healthy growth — an organization adopting an agent platform and building agents. Sprawl is that growth getting out of control: duplicate agents, agents without owners, and unapproved agents running in your environment, often without IT even knowing.

Does Agent 365 only work with agents built on Microsoft platforms?

No. From the start it was designed to work with any agent. Integration happens through the Agent 365 SDK, which is included in Microsoft’s Agent Framework, alongside a broad ecosystem of partners, ISVs, and AI platforms.

What happens when you block an agent?

Blocking removes the agent from anyone who has it (for example, in Copilot or Teams) for as long as it’s blocked — so it’s wise to notify your help desk or the agent’s owner that it’s temporarily out of service while you investigate the risk.

What licensing do we need?

Agent 365 requires an E5 prerequisite. You can get it bundled in the new E7 Frontier Suite (which includes the Entra Suite, Microsoft 365 Copilot, and Agent 365) or as a separate per-user subscription. The license is assigned to the user who builds or manages agents, not to the agents themselves.

ABOUT THE SPEAKERS

Ben Lockwood, a Technical Architect at Concurrency on the workplace enablement team, focuses on helping organizations drive agent adoption at scale — moving from experimenting with agents to embedding them securely into core enterprise operations.

Drew Johnson, a Senior Solution Engineer at Microsoft and a former Concurrency team member. As a Copilot engineer whose work spans both Copilot and security, he helps organizations observe, govern, and secure their agents with Agent 365.

TRANSCRIPT

Transcription Collapsed

Hi there. Good morning, good afternoon, good evening, wherever you are. Welcome to Agent 365, Governing the Workforce You Didn’t Hire. I am Ben Lockwood. I’m a technical architect with Concurrency in the workplace enablement team. And today we also have with us 0:0:30.97 –> 0:0:32.257 Ben Lockwood Drew Johnson, Drew. 0:0:34.817 –> 0:0:54.257 Drew Johnson Hello, yeah, Drew Johnson, Senior Solution Engineer at Microsoft. I’ve been there now about a year and five months, I want to say, so still kind of a newbie. I’m actually also a former employee for Concurrency, so I was excited to be able to come in and speak to you all today. 0:0:54.897 –> 0:0:55.457 Drew Johnson Pleasure. 0:0:57.857 –> 0:1:18.417 Ben Lockwood So the goal of this session is to talk about how we can support you in driving agents adoption at scale and moving from experimenting with agents to embedding them into the core of all enterprise operations. Agent 365 was built with one single purpose, to accelerate AI adoption by delivering visibility, control, and protection for rapidly evolving AI assets. 0:1:19.297 –> 0:1:27.337 Ben Lockwood The key to anchor on is simple. Agents need to be managed with the same rigor as users, apps, and devices. And Agent 365 is how we do that. 0:1:31.857 –> 0:1:52.337 Ben Lockwood So one quick note before we get started here, if you’re interested in staying connected with Concurrency, feel free to scan the QR code or search Concurrency Inc. in LinkedIn. On there, we’ll post which webinars we have going on, blogs, and any other information. So please feel free to get connected with us and learn more. 0:1:52.377 –> 0:1:54.417 Ben Lockwood learn more about what we can do and how we can help you. 0:2:3.617 –> 0:2:20.657 Ben Lockwood So agents are becoming ubiquitous. We are quickly entering a state where agents are no longer experimental. They are rapidly becoming a foundational layer for how work gets done, embedded in applications, automating workflows, collaborating with employees and each other, and acting on behalf of the business. 0:2:25.137 –> 0:2:45.497 Ben Lockwood Industry forecasts make the scale of this shift clear. Analysts project that there will be more than 1.3 billion agents in operation by 2028, signaling a massive acceleration from isolated assistance to fleets of autonomous agents operating across the enterprise. This is not a distant future scenario. It’s A near-term reality that IT leaders need to prepare for now. 0:2:46.337 –> 0:2:54.337 Ben Lockwood As agents proliferate, the challenge is no longer can we build agents, the challenge is can we manage them confidently and securely at scale. 0:2:58.377 –> 0:3:18.737 Ben Lockwood And once technology leaders start scaling agents, the same key questions are top of mind for most organizations. It starts with the most fundamental question. Can we track all agents that exist in an organization? Understand who and how is using agents and what agents are doing? Next, technology leaders are looking to establish guardrails 0:3:18.777 –> 0:3:39.97 Ben Lockwood and processes around who can onboard and manage agents and what those agents are allowed to do. And finally, security leaders are asking questions whether those agents are properly protected. Do we understand what risks are targeting those agents? What resources and data can they access? And are those properly protected too? Without this foundation, 0:3:39.377 –> 0:3:47.137 Ben Lockwood Agent adoption can quickly lead to sprawl, unmanaged access, and operational risk, and threaten the productivity gains that agents promise. 0:3:51.937 –> 0:4:0.257 Ben Lockwood Now let’s make this a little more concrete, because Agent Sprawl isn’t a single problem. It compounds across 3 distinct surfaces, each with its own risk profile. 0:4:1.137 –> 0:4:22.777 Ben Lockwood First, we have SaaS agents. Employees are discovering and adopting AI agents through the web every day, often without IT ever knowing. Think of this as the next evolution of shadow IT. The questions are here. What agents are employees actually using via the internet? What are the risk levels of those agents? And critically, what sensitive information is being shared with them? 0:4:23.457 –> 0:4:28.497 Ben Lockwood Without visibility, every one of these interactions is a potential data leak waiting to happen. 0:4:30.97 –> 0:4:49.857 Ben Lockwood Second, we have endpoint agents. This is where the risk gets more tangible. Employees are installing and running agents directly on their devices, laptops, desktops, and mobile. These agents may have deep access to local files, credentials, and system resources. The questions shift to what security guardrails are built into those agents. 0:4:49.977 –> 0:4:58.177 Ben Lockwood What access and permissions are employees granting? An over-permission agent on an endpoint is essentially a new attack vector sitting right on the device. 0:4:59.777 –> 0:5:18.577 Ben Lockwood Third, there’s cloud agents. Developers across your organization are building and deploying agents on various cloud and AI platforms, often across multi-cloud environments. These are the agents with the deepest integrations. They connect to APIs, MCP servers, data stores, and other agents. 0:5:18.977 –> 0:5:31.777 Ben Lockwood The questions here are about vulnerabilities that could be exploited by attackers and whether the platforms themselves provide sufficient built-in guardrails. A single misconfigured cloud agent can become an entry point into your broader infrastructure. 0:5:33.137 –> 0:5:53.457 Ben Lockwood These 3 surfaces don’t just add risk, they multiply it. A SaaS agent that an employee grants access to can reach endpoint data. A cloud agent can invoke loads or tools that touch SaaS and endpoint resources. The sprawl compounds because agents interact across these boundaries in ways that traditional security models weren’t designed for. 0:5:57.57 –> 0:6:9.617 Ben Lockwood These are the exactly the challenges that are being solved with Agent 365. Agent 365 is the control plane for agents that enable the scaling of adoption of agents with proper oversight and guardrails. 0:6:13.857 –> 0:6:32.97 Ben Lockwood Agent 365 helps you move from agent experimentation to enterprise scale operations with three core capability areas. First comes observe, because you cannot control what you cannot see. So Agent 365 gives you the full picture of all agents in your organization, their usage patterns, 0:6:32.297 –> 0:6:35.377 Ben Lockwood And behaviors, so you can take action based on what you see. 0:6:36.497 –> 0:6:57.137 Ben Lockwood Next, govern, which means establishing guardrails for agents and users, creating IT-led processes, and having the right compliance to be audit ready. And finally, secure. Secure agents, because just as any other asset in your environment, agents need strong protections, from protecting their identities and access 0:6:57.217 –> 0:7:1.377 Ben Lockwood to safeguarding data they use in defending them against threats and vulnerabilities. 0:7:2.337 –> 0:7:7.697 Ben Lockwood Now let’s go deeper into what you already do with the Agent 365 in each of those capability areas. 0:7:11.377 –> 0:7:30.177 Ben Lockwood Let’s start with observability. This is the most fundamental set of capabilities in Agent 365 that makes everything else possible. Agents come from many different sources in most organizations. Everyone from professional developers with pro code tools to AI savvy knowledge workers are creating agents. 0:7:30.657 –> 0:7:39.217 Ben Lockwood Plus, users are increasingly adopting agents accessible online, which makes it easy to lose visibility into existing and unmanaged shadow agents. 0:7:43.57 –> 0:8:1.817 Ben Lockwood Agents are coming from everywhere. Users are using SaaS agents. Users are installing and running agents on their devices. And developers are building and deploying agents in multi-cloud, multi-platform environments. But for most organizations, the core question is still unanswered. What agents exist in my organization and who is using them? 0:8:2.497 –> 0:8:16.497 Ben Lockwood That lack of visibility creates immediate risk. You can’t track usage, understand behavior, or see how agents connect across your environment. And without that foundation, it’s impossible to govern or secure agents at scale. 0:8:30.537 –> 0:8:50.457 Ben Lockwood The moment we know what agents exist, the most pressing question is how to get those agents under control. Governance isn’t about slowing teams down. It’s about putting the right guardrails in place from day one. Without governance, agent adoption becomes inconsistent and unsustainable. Reviews and ownership vary, lifecycle management breaks down, 0:8:50.657 –> 0:9:9.337 Ben Lockwood and IT ultimately loses confidence in the system. Agent 365 extends IT’s existing policy-driven governance to agents, controlling who can create and onboard them and enforcing guardrails as they evolve, so innovation can scale with the right controls in place. The result is governance that enables scale 0:9:9.537 –> 0:9:16.17 Ben Lockwood instead of blocking it. IT can say yes to agent innovation because the right controls are already in place. 0:9:21.857 –> 0:9:41.977 Ben Lockwood As we’ve discussed, agents can span across SaaS, local, and cloud environments and operate through APIs and MCPs. So governance quickly becomes complex. The key question is, what agents can organizations manage and how can they do it at scale? Without the right governance, risky or unethical agent interactions go undetected. 0:9:42.897 –> 0:9:55.697 Ben Lockwood You can’t retain or investigate activity for compliance, and you lose visibility into what agents are actually doing. At that point, organizations can experiment with agents, but they can’t confidently scale them. 0:10:5.457 –> 0:10:24.297 Ben Lockwood The 3rd capability area that is at the heart of Agent 365 is security. Because agents are ubiquitous, they exponentially expand surface area that must be protected. Without proper security, they can become a new pathway for data exposure, misuse, or unintended behavior, often without obvious signs until damage is already done. 0:10:25.137 –> 0:10:32.977 Ben Lockwood And because they behave more like users, but structurally are more like apps, our security model must count for those unique characteristics of agents. 0:10:36.417 –> 0:10:55.137 Ben Lockwood The agent era introduces new layers of interaction and risk. Users can now create their own agents, adopt SaaS-based agents, or deploy agents directly on endpoints, rapidly increasing agents for all across the enterprise. And while the classic protections still matter, securing human-to-agent prompts and agent-to-human responses 0:10:55.457 –> 0:11:14.937 Ben Lockwood They’re not enough on their own. Why? Because agents have new interaction paths. They interact with other agents, tools, and apps, creating an expanded threat landscape with two dimensions of security challenges. One, increased interaction points across agent to agent, agent to tool, and agent to app. 0:11:15.457 –> 0:11:29.857 Ben Lockwood Communications requiring expanded monitoring. Two, broader threat categories beyond data oversharing and leakage, including identity and privilege abuse, tool misuse and exploitation, and insecure inter-agent communication. 0:11:31.457 –> 0:11:38.417 Ben Lockwood Agent 365 was built to address this shift, helping you observe, govern, and secure agents at scale. 0:11:39.537 –> 0:11:44.17 Ben Lockwood Now let’s break that down and understand these new threat vectors and scenarios in the Agent era. 0:11:52.857 –> 0:11:57.457 Ben Lockwood So let’s take a look at a demo right now of Agent 365. Drew. 0:11:58.817 –> 0:12:20.97 Drew Johnson All right. Okay, so before we get into the demo, one of the things I wanted to share is that there’s two main things that we see with organizations who are interested in Agent 365. You have what’s called Agent proliferation, and then you also have what’s called Agent sprawl, which Ben touched on earlier. So essentially, Agent proliferation is 0:12:20.177 –> 0:12:44.897 Drew Johnson the act of an organization starting to adopt an Agent platform. They have several different agents that are being built. It’s, you know, essentially AI growth. And it’s one of the things that we kind of refer to as frontier transformation, right? So you have that, but then you also have what’s called agent sprawl. So agent sprawl is essentially a matter of 0:12:45.57 –> 0:13:5.297 Drew Johnson agents just being completely out of control, right? You got duplicate agents, you got agents without owners, you got people, you know, using agents that probably aren’t even necessarily approved. So you got all those kind of things that can absolutely exist in your environment and sometimes a lot of IT teams don’t even know it. That’s kind of where Agent 365 comes into play. So 0:13:5.857 –> 0:13:28.897 Drew Johnson One of the few things that I want to touch on as far as people that may be interested in getting it for the organization, the first thing is Agent 365 does require E5 license prerequisite in order to use it. That’s one of the main things that the tenant has to have. More importantly, if you purchase Agent 365, you have two ways of doing it. You can do it by either E7 license, which is 0:13:29.17 –> 0:13:48.497 Drew Johnson bundle with Copilot, you know, your typical E5 services that you already get. And let’s see, Copilot, Agent 365, there’s some other things in there too. And then you also could do, if you wanted to do a separate SKU, you can do a $15 per month per user SKU as well. 0:13:50.177 –> 0:14:8.377 Drew Johnson A lot of people were confused about Agent 365, thinking that it initially was assigned to agents. It’s not. It’s actually assigned to the user. And you mainly would purchase Agent 365 for people that, you know, are building agents A lot. If they are managing agents, 0:14:8.977 –> 0:14:26.737 Drew Johnson If they have, you know, several agents they have access to, those are the kind of people that you would consider getting an Agent 365 license for. So let me, I’m going to take you through a quick click-through demo, and then I’m going to show you my demo tenant and show you some more details about Agent 365. 0:14:28.257 –> 0:14:28.737 Drew Johnson No. 0:14:34.657 –> 0:14:38.897 Drew Johnson All right, so you guys should see the screen, put my other screen up. 0:14:42.417 –> 0:14:43.377 Drew Johnson Second. 0:14:47.57 –> 0:15:5.937 Drew Johnson All right, so here’s just kind of the home interface of Agent 365, right? So you access it in the admin center on the left of the top up there, you would click on agents. And then this is basically the homepage, right? So this is just a quick snapshot. Basically, Agent 365 0:15:6.57 –> 0:15:26.737 Drew Johnson kind of took pointers from all the other offerings that we have. So you have, you know, Agent 365 that can exist in Purview. You have it where it can exist in Entra, and then of course the homepage where the Agent 365 lives. We wanted to do that because we wanted to make the 0:15:27.137 –> 0:15:39.897 Drew Johnson the migration to Agent 365 seamless and not so confusing for admins. And obviously we built it on a similar interface that people are already used to. 0:15:43.57 –> 0:16:2.977 Drew Johnson All right, so here’s just a quick breakdown of where the agents are, how they’re created, how they’re shared by users. You can see here, you got information about the publishers, active users over time. It gives you, you know, basically everything you need to see, right? It’s all here. 0:16:3.297 –> 0:16:5.537 Drew Johnson So I’m going to click on all agents. 0:16:7.497 –> 0:16:28.737 Drew Johnson And this is basically going to take you to essentially all the agents that you have in your environment. Now, every agent is essentially onboarded using a sort of registry system. Every agent is assigned a unique ID so that they can be identified, just like an end user or a device, right? You get 0:16:29.377 –> 0:16:47.857 Drew Johnson an ID that you can reference that agent. And basically that ID is unique to that specific agent. So I’m going to click this first one here, Zava Fabric Supplier. And here’s more details about some stuff you can see, right? So if I click the Users tab, I can see 0:16:48.497 –> 0:17:2.97 Drew Johnson All the people that are a part of this will have access to this agent. If you notice, there’s a sales department in there, so that’s actually a group. But you also have users. So you have several different people that have access to this, right? 0:17:3.177 –> 0:17:23.377 Drew Johnson So then if I go over the data and tools, you get more details. This is honestly just the great thing about Agent 365 is it’s a ton of detail, right? All things that matter to your IT admins when it comes to Governing and protecting your environment. I’m going to click on security and compliance. So as you can see, 0:17:23.537 –> 0:17:43.897 Drew Johnson You have more details about the agents that are being monitored, anything that’s being protected from sensitive data. And then you can even jump between different admin centers right from this page. So you have like Microsoft Defender protections. If you click that, it’ll take you over to Entra, take you over to Defender to see additional details. 0:17:44.897 –> 0:18:3.937 Drew Johnson Typically, when us here at Microsoft present Agent 365 to a customer, we usually partner with our security pals because Agent 365 is mainly a security feature. However, because I am considered a copilot engineer, 0:18:4.257 –> 0:18:12.577 Drew Johnson We have a say so and a talk track for it as well, just because it kind of crossed paths with both copilot and security. 0:18:16.177 –> 0:18:36.657 Drew Johnson So on this screen, you can just get a picture or a snapshot of the permissions. So as you can see down here, the Microsoft Graph APIs, these permissions probably look similar to some of the admins. This kind of dictates what kind of rights these agents have, what they’re allowed to do. Obviously, you have toggles to turn these on and off in a moment’s notice. 0:18:36.937 –> 0:18:45.297 Drew Johnson which is great. Again, it’s just high visibility into everything as it relates to agents. 0:18:47.217 –> 0:19:6.937 Drew Johnson So if I go back to the homepage, I’m going to click on Agent at Risk. We want to take a look at that. So you can set up alerts so that your admin is automatically notified if there is risk with an agent that exists in your environment. So if I click on this one, change management agent, let’s see what’s going on with this one. 0:19:7.57 –> 0:19:27.457 Drew Johnson giving us an error. So it says high risk detected. High risk and agents may be a security threat for your organization. Risks are only available for 90 days. Reach out to your security admin to investigate to resolve any risks or block this agent. Right. So even if you don’t know what to do with this agent right now, you have the option to block it. 0:19:27.857 –> 0:19:46.17 Drew Johnson until you figure out exactly what’s wrong with it. You know, it’s pretty critical that that’s done as soon as possible, because again, you don’t know exactly what’s causing the risk, and you need to be able to figure it out, and you need to stop use of it while you investigate. So if we click block, 0:19:47.697 –> 0:20:7.457 Drew Johnson You know, again, just a normal window like you would see whenever you’re, you know, toggling a setting on an admin center. If you block this agent, people in your organization can’t install or use it. It will be removed from any user who has already installed it. So block agents, I’m going to hit save. And now that agent is completely blocked from being able to access the environment. Now, 0:20:7.537 –> 0:20:19.937 Drew Johnson Without Agent 365, right? You have agents that exist out in your environment that could be doing things like that, and you don’t have any notification or way of knowing that this agent is, you know, essentially causing potential risk. 0:20:22.177 –> 0:20:25.857 Drew Johnson I’m going to click on this next agent here, Zava Procurement Agent. 0:20:27.297 –> 0:20:47.137 Drew Johnson And what I want to do is what you can see a lot of times to an agent 365 is that you will have a lot of what’s called ownerless agents. And that essentially means that there’s an agent that hasn’t been assigned an owner for whatever reason. Maybe someone created in Copilot Studio and then just kind of left it be. That is also one of the reasons that 0:20:47.777 –> 0:21:8.697 Drew Johnson Agent governance is important. I’ve seen a ton of organizations who set up, for instance, let’s say they’re using Service Now. They’ll set up a page where you have to submit a request for an agent, and then it goes through a review process, and then it eventually deploys to the environment if it’s approved. 0:21:9.137 –> 0:21:28.457 Drew Johnson That’s the sort of thing that you want to watch out for. So if you, you know, in conjunction with using Agent 365 and having a proper governance or, I guess, application process set into place, this gives you the best outlook on keeping your environment secure. I’m going to click here. I’m going to click assign new owner. 0:21:29.57 –> 0:21:46.17 Drew Johnson And I’m going to look for owner, click search. I’m going to add Robin as the owner of this agent. So just like that, now you have an agent that is not, that does not have an owner. Agent now has an owner assigned to it. 0:21:50.97 –> 0:22:10.377 Drew Johnson So another thing you can also do is rules. Now, some people might be familiar with rules when it comes to exchange or I guess mainly exchange, where you can set rules within your tenant, but that’s also an option for Agent 365 as well. So I’m going to click on this, because basically what I want to do is I want to make 0:22:10.657 –> 0:22:29.577 Drew Johnson a rule that’s going to automate some of the agent features here. So I’m going to click on add rule. I’m going to give it a name. So we’ll call it reassign only agents to manager, right? Obviously, you give it a description, let other admins know what the rule is. 0:22:29.697 –> 0:22:41.777 Drew Johnson does and does and who it applies to. Assign an owner to a manager. Again, this is important when you have agents that are just kind of sitting out there and don’t have any. 0:22:44.257 –> 0:23:6.497 Drew Johnson don’t have anyone assigned to it. The other thing you want to think about as well is agent lifecycle. And essentially lifecycle means that you can set an agent where, you know, if it’s not used in a certain amount of time, you can, you know, go through and request that whoever is still using the agent, if they actually still need it or they don’t, or if they don’t need it and… 0:23:6.577 –> 0:23:9.17 Drew Johnson you know, let you know, and then you can just remove it from your environment. 0:23:10.137 –> 0:23:11.297 Drew Johnson So I’m going to click next here. 0:23:12.737 –> 0:23:26.977 Drew Johnson And then basically this is just kind of giving you a final look in details before we turn the rule on. These are agents that are essentially connected to the the rule. So I’m going to click turn on rule. 0:23:28.577 –> 0:23:31.857 Drew Johnson And just like that, the rule is on. So easy and simple. 0:23:34.777 –> 0:23:43.457 Drew Johnson All right, so going back to the all agents page, and again, just kind of retouching on the agent life cycle, I want to click on map up here. 0:23:44.817 –> 0:24:3.457 Drew Johnson And this is really cool. A lot of customers really enjoy seeing this visual. So you can basically zoom in and see the connection map, which shows how each agent is interacting with other agents, right? That’s also something that’s going to be critical. If you have an agent that has certain permissions to do certain things or access certain 0:24:5.57 –> 0:24:22.97 Drew Johnson access certain data in your environment. You also want to know if there are other agents that are connected to that agent somehow and possibly able to feed information from the other agent. So I’m going to click next. And then it just kind of goes into a deep dive into the agent. So I’m going to click on this bubble over here. 0:24:23.217 –> 0:24:40.97 Drew Johnson And you can see you have this comms agent, but then you also have, it’s connected to the distribution agent, it’s connected to the compliance agent, the learning guy, and then the procurement strategy agent, right? So all these agents are essentially connected to this agent in some way. They’re dependents of this agent. 0:24:42.817 –> 0:25:1.937 Drew Johnson If I go over to the comms agent, I basically can get performance stats on the agent, how many active users per day, some of the sessions that have happened, exceptions, assisted hours. So all these details here will, you know, give you, you know, a better look at 0:25:3.377 –> 0:25:15.257 Drew Johnson what the agent is actually doing. And honestly, if you go into this page and you don’t see any real activity, that lets you know that this agent is potentially a candidate to be removed from your environment because it’s not being used. 0:25:16.417 –> 0:25:23.137 Drew Johnson So that’s it for this part. So I’m going to stop sharing and I’m going to go to my demo tenant just to show you guys real quick. 0:25:24.657 –> 0:25:26.177 Drew Johnson Some stuff in there. 0:25:30.377 –> 0:25:30.657 Drew Johnson Hey. 0:25:32.257 –> 0:25:51.57 Drew Johnson All right, so we actually had some issues recently where we it was it was a little difficult to get our demo tenant set up in a way where we can actually show it and and and you know really be impactful to people that see it. So, we eventually… 0:25:51.97 –> 0:26:10.617 Drew Johnson we’re able to figure out a way to get hydrated content into our demo tenant. So this is all fake content, it’s not real. This is just generic information about Agent 365. So click over here on Shadow AI. So Shadow AI is essentially where you have people that are using agents that are… 0:26:10.897 –> 0:26:26.737 Drew Johnson are more than likely not approved or not something that’s explicitly not allowed in your environment. So your Agent 365 has the ability to detect information like that, and you’ll see it all here on this pane. 0:26:27.937 –> 0:26:35.297 Drew Johnson I’m gonna move over to, let’s see, actually I’m gonna go to, I’m gonna go to Andrew real quick. 0:26:37.937 –> 0:26:49.457 Drew Johnson So earlier I was talking about the, I was talking about the registry. So this is the part where the agents are actually onboarded. If I go over to. 0:26:52.257 –> 0:26:52.337 Drew Johnson Ann. 0:26:54.17 –> 0:26:56.657 Drew Johnson Is this actually you do this? 0:27:0.657 –> 0:27:2.57 Drew Johnson Agent IDs, yeah. 0:27:4.577 –> 0:27:24.657 Drew Johnson Okay, so this is essentially the homepage for your agent identities. Again, each agent is assigned a unique ID. So if I click on, here’s, actually, technically this is what’s called blueprints. But if you, if you’re curious about 0:27:25.657 –> 0:27:38.737 Drew Johnson you know, your agent’s identity, what they’re doing, or, you know, when they’ve been created. Any of that information is going to exist right here. So as you can see, I have several agents that I’ve onboarded. So if I click on it. 0:27:41.537 –> 0:27:50.657 Drew Johnson This looks very similar to IT admins, right? You have the options for conditional access, permissions, because again, agents are basically treated just like a normal user. 0:27:53.217 –> 0:28:0.417 Drew Johnson And then let me go back to here. Let me see, I think it was one other thing I wanted to show you. Let’s see, tools. 0:28:1.697 –> 0:28:2.337 Drew Johnson Actually. 0:28:5.697 –> 0:28:7.937 Drew Johnson Oh, you guys saw the map already. 0:28:10.537 –> 0:28:11.297 Drew Johnson Not there. 0:28:17.857 –> 0:28:23.57 Drew Johnson You go down real quick. I’m trying to get you guys to see some agents that. 0:28:25.57 –> 0:28:27.857 Drew Johnson that have some additional risk so that you can see it in real time. 0:28:32.897 –> 0:28:34.257 Drew Johnson Oh, that was in here. 0:28:37.617 –> 0:28:56.737 Drew Johnson Well, basically, what I was going to show is just a more detailed look at what we saw earlier, which is, you know, seeing agents that have risks associated with them. Again, you have several different ways you can go about blocking and securing those agents. You can go through and change the permissions out. 0:28:57.297 –> 0:29:7.617 Drew Johnson You can also, another great thing is you can give agents conditional access policies. You can add them to, you know, essentially whatever policies you have in your environment. It’s treated just like an actual user. 0:29:8.737 –> 0:29:13.777 Drew Johnson So I’m going to pass it back to Ben. Stop sharing. 0:29:20.497 –> 0:29:40.537 Ben Lockwood Real quick, Drew, from what I can tell, there’s a question. If you block an agent, is there something telling users it’s temporarily out of service so that calls don’t start coming into operations slash help desk? My understanding is that it basically disappears the agent or, you know, they lose access to it. So if they do have it as an agent and 0:29:32.737 –> 0:29:33.137 Drew Johnson Has it? 0:29:40.977 –> 0:29:53.57 Ben Lockwood in copilot or in Teams, then it just is gone essentially for while it’s blocked. And so yeah, you probably would get a call or a ticket saying where to go. 0:29:46.657 –> 0:29:47.57 Drew Johnson Yeah. 0:29:52.337 –> 0:30:9.937 Drew Johnson Yeah, and that’s a good question, Jerry. So yeah, if an agent is blocked, I mean, I don’t, I haven’t actually, you know, tried to access a blocked agent, but I would imagine that, you know, even if there isn’t any, you know, any notification that says that the agent 0:30:10.257 –> 0:30:25.457 Drew Johnson is out of service, they’re going to know because they can’t use it. So I mean, you’re probably going to get calls anyway. So this would be a great solution for, or I guess, basically trying to. 0:30:26.617 –> 0:30:45.297 Drew Johnson Stop it, stop the storm before it starts. You know, reach out to either your help desk teams or, you know, maybe even who specifically owned the agent, you know, giving them some sort of generic e-mail saying, hey, this agent is out of service temporarily, blah, blah, blah. You know, something, just let them know that, hey, don’t. 0:30:45.377 –> 0:30:54.977 Drew Johnson continue calling to the help Desk, trying to figure out what’s going on with the agent. We’re working on it and we’ll be in touch when we have an update. So, but great question. 0:30:57.777 –> 0:30:59.137 Ben Lockwood Awesome. Thank you, Drew. 0:31:0.17 –> 0:31:0.657 Drew Johnson No Bob. 0:31:1.857 –> 0:31:11.977 Ben Lockwood So Agent 365 is not just for agents that were built with Microsoft AI builder platforms. From the start, Agent 365 was designed to work with any agent. 0:31:13.457 –> 0:31:37.697 Ben Lockwood and already have the broad ecosystem of partners, platforms, and agent builders that are connecting through the Agent 365 ecosystem. This is more than just Microsoft tools. It’s a full ecosystem of ISVs, AI platforms, and enterprise SaaS providers coming together to enable agents to work securely and effectively across your organization. All it takes is integration with Agent 365 SDK, which is also included into Microsoft’s Agent 0:31:37.737 –> 0:31:49.697 Ben Lockwood framework. Whether you’re using Microsoft for solutions or tools from across the industry, Agent 365 provides a unified, secure foundation for bringing all of those agents into your environment in a consistent, governed way. 0:31:56.737 –> 0:32:16.417 Ben Lockwood The fastest path to getting agents under control is by managing them in a similar manner to managing users. With Agent 365, you extend existing infrastructure and protections from people to agents and integrate agent management into existing workflows with familiar Microsoft solutions across a distributed control plane. So the more 0:32:16.817 –> 0:32:25.457 Ben Lockwood of these different tools that you’re implementing within your organization, the greater the visibility is going to be within Agent 365. 0:32:31.377 –> 0:32:51.657 Ben Lockwood Agent 365 helps you move from scattered agent pilots to a governed, repeatable rollout across your enterprise. It speeds deployment across teams, plugs agents into the workflows that actually drive outcomes, and adds the controls that IT cares about so you cut misconfigurations, user error, and security gaps. This results in faster time to value, 0:32:52.17 –> 0:32:57.497 Ben Lockwood lower operational risk, and the confidence to scale AI as a standard capability across the business. 0:33:2.337 –> 0:33:15.297 Ben Lockwood So as Drew talked about a little bit, this is offered through the new E7 Frontier Suite. And he did mention, you know, that E5 is necessary in order to have this. 0:33:17.137 –> 0:33:24.577 Ben Lockwood That new E7 includes the Entra Suite, 365 Copilot, as well as Agent 365. 0:33:29.297 –> 0:33:35.937 Ben Lockwood Just another look here at what you get with E7 versus the individual on the list prices. 0:33:37.57 –> 0:33:49.57 Ben Lockwood So an E5 is $60. Entre suite is $12. copilot is $30. Agent 365, 15, or you can do it all in the E7 suite for 99. 0:33:50.97 –> 0:34:8.577 Drew Johnson Yeah, and real quick, just to touch on that, Ben. So if you are considering, let’s say you’re an organization that still has E3, which I feel really bad for you if you still have E3. But if you’re an organization that has E3, for example, and you’re looking to upgrade to E5, but you also are considering copilot, 0:34:9.57 –> 0:34:28.497 Drew Johnson Depending on how the pricing structure is, it may be better to just go to E7 because you get that bundle. And then also, again, you have that additional security for Agent 365. If you use E5 and you use a per user per month Agent 365 license, obviously, that’s good. That’s going to give you 0:34:29.137 –> 0:34:37.537 Drew Johnson A pretty, you know, pretty secure environment, but again, if you, you know, simply just bundle all that together, you probably could save some money. 0:34:39.777 –> 0:34:40.657 Drew Johnson Sorry, Ben, go ahead. 0:34:40.817 –> 0:34:41.697 Ben Lockwood Nope, you’re good. 0:34:44.97 –> 0:35:2.177 Ben Lockwood All right, so next steps. Are you interested in a Agent 365 readiness assessment? Discover what’s required to securely deploy governance scale Agent 365 across your organization with a personalized readiness assessment. We also have a survey. Let us know 0:35:3.217 –> 0:35:16.337 Ben Lockwood how you think we did. There might be an option to fill out what other topics you’re interested in. I don’t know. I forget what’s all in that survey. But please fill out the survey. Let us know how things went. 0:35:17.777 –> 0:35:19.937 Ben Lockwood Give you a minute there to scan that. 0:35:31.297 –> 0:35:38.657 Ben Lockwood And lastly, just want to say thank you for coming and watching our webinar. Please remember to follow us on LinkedIn. 0:35:39.617 –> 0:35:44.177 Ben Lockwood With that, I appreciate your time. Have a great rest of your day.