{"id":22560,"date":"2026-03-09T06:00:00","date_gmt":"2026-03-09T13:00:00","guid":{"rendered":"https:\/\/www.microsoft.com\/insidetrack\/blog\/?p=22560"},"modified":"2026-06-17T09:24:18","modified_gmt":"2026-06-17T16:24:18","slug":"shaping-ai-management-at-microsoft-with-agent-365-and-copilot-controls","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/insidetrack\/blog\/shaping-ai-management-at-microsoft-with-agent-365-and-copilot-controls\/","title":{"rendered":"Shaping AI management at Microsoft with Agent 365 and Copilot controls"},"content":{"rendered":"\n

AI is moving fast at Microsoft. Every month, we\u2019re discovering new ways that our employees are using Microsoft 365 Copilot and rapidly emerging agentic tools to work smarter, automate routine tasks, and unlock new patterns of productivity.<\/p>\n\n\n\n

As our ecosystem of AI tools expands, so does our responsibility and opportunity. We have to guide the process with the right structure, clarity, and confidence. <\/p>\n\n\n\n

\"A<\/figure>\n\n\n\n
\n

“With Agent 365, IT leaders can confidently embrace this innovation through a unified control plane that provides the capabilities that enterprises need to ensure agents are governed, observable, and secure\u2014regardless of which tools, frameworks, or models were used to create them.”<\/p>\nBrian Fielder, vice president, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n

We approach the governance of AI as a task we\u2019re shaping in real time while observing the different ways our people are using AI in their daily work.<\/p>\n\n\n\n

That\u2019s the advantage of being Customer Zero<\/a> here in Microsoft Digital, the company\u2019s IT organization. We\u2019re living this transformation across Microsoft 365 every day, evolving our governance model alongside the evolution of AI and agents.<\/p>\n\n\n\n

\u201cWith Agent 365, IT leaders can confidently embrace this innovation through a unified control plane that provides the capabilities that enterprises need to ensure agents are governed, observable, and secure\u2014regardless of which tools, frameworks, or models were used to create them,” says Brian Fielder, vice president of Microsoft Digital.<\/p>\n\n\n\n

Our governance approach is built around two complementary control planes: Microsoft Agent 365 for agents and Copilot controls for Microsoft 365 Copilot.<\/p>\n\n\n\n

\"A<\/figure>\n\n\n\n
\n

\u201cWe\u2019ve seen the rapid pace of innovation firsthand. As Copilot evolves and agents expand, the control planes we use must evolve also. New AI and agent capabilities raise the bar for governance and management, so at Microsoft Digital, we\u2019re working with our product teams to evolve the management to keep the company secure, informed, and ready for whatever comes next.\u201d<\/p>\nDavid Johnson, principal architect, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n

These control planes are supported by the four fundamental concepts that we apply to every enterprise system we operate: security, governance, management, and observability.<\/p>\n\n\n\n

\u201cWe\u2019ve seen the rapid pace of innovation firsthand,\u201d says David Johnson, principal architect in Microsoft Digital. \u201cAs Copilot evolves and agents expand, the control planes we use must evolve also. New AI and agent capabilities raise the bar for governance and management, so at Microsoft Digital, we\u2019re working with our product teams to evolve the management to keep the company secure, informed, and ready for whatever comes next.\u201d<\/p>\n\n\n\n

This model gives us a consistent way to support new capabilities, encourage responsible experimentation, and help our employees adopt AI and agents with fewer hurdles.<\/p>\n\n\n\n

Expanding our AI governance practices<\/h2>\n\n\n\n

As AI use evolves within our organization, we\u2019re seeing clear patterns emerging. Copilot goes well beyond chat. It can execute tasks, create and modify content directly inside apps, connect systems, and coordinate multi\u2011step work through agents. The AI ecosystem is becoming more effective at boosting productivity with model choices, agent-to-agent orchestration, and agent mode within applications that leverage natural language to complete tasks.<\/p>\n\n\n\n

These patterns are exciting, move fast, and expand how we think about governance.<\/p>\n\n\n\n

The shift became clear as teams across Microsoft began experimenting with new AI capabilities in the last few years. Accelerating Copilot usage showed us how quickly people adopt tools to help them work better and faster. Rapid agent growth showed us how much value workers get when AI takes on more complex, multi\u2011step tasks. These expansions pushed us to evolve our security, governance, and management approaches alongside the technology.<\/p>\n\n\n\n

That\u2019s what led us to define two complementary control planes for Copilot and agents\u2014not because one replaces the other, but because they serve complementary roles in the ecosystem. Copilot goes beyond chat, surfacing intelligence directly inside apps, workflows, and context to help people work smarter in the flow of their apps. Agents take on broader responsibilities across services, teams, and data boundaries.<\/p>\n\n\n\n

By recognizing the different types of work that Copilot and agents do, we\u2019re better equipped to manage and govern them. We can apply consistent principles, tailor the controls to each type of tool, and give employees a clearer understanding of how each AI capability behaves. It\u2019s an approach that grows with technology, instead of forcing everything into a single frame.<\/p>\n\n\n\n

Building governance on foundational pillars<\/h2>\n\n\n\n

As Copilot and agents expand across Microsoft 365 and the rest of our product offerings, we\u2019ve anchored our approach on the fundamentals of security, governance, management, and observability. These principles have shaped our enterprise systems for years. What\u2019s changing is how we apply them to a fast\u2011moving AI ecosystem.<\/p>\n\n\n\n

Security and governance<\/h2>\n\n\n\n

Security and governance are the baseline for us at Microsoft. Every new capability\u2014whether it\u2019s Copilot helping you draft, find, or create content, or an agent running an automated workflow\u2014must adhere to security and governance principles.<\/p>\n\n\n\n

\"A<\/figure>\n\n\n\n
\n

\u201cThe Microsoft 365 admin center is becoming the place where controls come together. Policies, observability, and configuration are in a single experience, so admins don\u2019t have to hunt across multiple portals. That consolidation makes it easier for us to understand how AI is behaving in our tenant and what controls we have available to guide it.\u201d<\/p>\nMike Powers, senior systems engineer and AI admin, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n

Products like Microsoft Purview and Defender allow us to better understand what data our AI tools are accessing, for how long, and where additional guardrails might be needed as features and usage evolve.<\/p>\n\n\n\n

Management<\/h2>\n\n\n\n

Management completes the foundation, and measurement is how we track our progress.<\/p>\n\n\n\n

As AI tools take on more responsibility, we needed a unified way to manage access, lifecycle, and configuration. Agent 365 is evolving the Microsoft Admin Center to serve as a central focal point for agent management and observability. Agent 365 brings together agent information and controls that were previously scattered across different admin experiences and puts them in one coherent place.<\/p>\n\n\n\n

\u201cThe Microsoft 365 admin center is becoming the place where controls come together,\u201d says Mike Powers, a senior systems engineer and AI admin in Microsoft Digital. \u201cPolicies, observability, and configuration are in a single experience, so admins don\u2019t have to hunt across multiple portals. That consolidation makes it easier for us to understand how AI is behaving in our tenant and what controls we have available to guide it.\u201d<\/p>\n\n\n\n

It\u2019s how we track adoption, quality, and business value like time saved and reduction in operational costs. It\u2019s how we identify what\u2019s working, where to invest next, and how we can guide product teams with real\u2011world insights. We look carefully at active agents, usage patterns, assisted hours, sentiment, and the outcomes our people achieve with AI. Different audiences share the same goal: using telemetry to make AI better.<\/p>\n\n\n\n

Together, these principles allow us to evolve our governance model without slowing innovation. They give us a steady foundation in a rapidly expanding environment\u2014one where Copilot and agents will continue to grow, intersect, and unlock new ways of working.<\/p>\n\n\n\n

Observability with Microsoft Agent 365<\/h2>\n\n\n\n

The widespread use of agents is an accelerating trend here at Microsoft. We use them to automate multi\u2011step tasks, build applications in plain language, connect systems, and streamline work that previously depended on manual coordination.<\/p>\n\n\n\n

As the number of agents grows and becomes more autonomous, we need a management approach that matches their scale and autonomy. That\u2019s what Microsoft Agent 365<\/a> gives us\u2014a control plane designed for AI and agentic workloads that operate across platforms and traditional admin boundaries.<\/p>\n\n\n\n

Agent 365 provides a registry for agents that lets us discover and understand how agents behave across Microsoft 365. It shows us who built them, who can use them, and what data they can access. From a single admin console, we can observe and manage agents created across different platforms. Day to day, Agent 365 gives AI admins agent observability we didn\u2019t have before, and a way to connect insight to action.<\/p>\n\n\n\n

\u201cAgents represent a significant and growing workload that tenant administrators manage as part of day\u2011to\u2011day operations,\u201d Powers says. \u201cAgent 365 helps bring clarity to a diverse and rapidly scaling agent population by providing a centralized place to observe and manage how agents operate. This centralized approach is bringing together admin teams like never before so we can apply broad expertise to agent management.\u201d<\/p>\n\n\n\n

That clarity matters.<\/p>\n\n\n\n

Agents behave differently than Copilot experiences. They can run continuously, trigger processes automatically, and touch systems across organizational boundaries. By treating them as advanced workloads, we can apply governance that supports experimentation without losing control over the ecosystem.<\/p>\n\n\n\n

Agent 365 gives teams the confidence to build agents, knowing there\u2019s a clear, consistent framework behind them. It helps ensure agents scale responsibly, are discoverable, and align to the enterprise patterns that keep Microsoft secure and productive.<\/p>\n\n\n\n

Keeping track of Copilot controls<\/h2>\n\n\n\n

We rely on Copilot controls<\/a> to give us a unified way to govern how different Copilot experiences show up for employees.<\/p>\n\n\n\n

Copilot controls aren’t a single product. It\u2019s a fabric of controls, insights, and guardrails that help us guide Copilot usage as it grows. It brings together settings, reports, and policies that once lived across separate admin surfaces and connects them into one coherent system.<\/p>\n\n\n\n

\"A<\/figure>\n\n\n\n
\n

\u201cCopilot controls bring everything into one place, so admins don\u2019t have to jump across different reports. It gives them a holistic view of Copilot health. That includes licenses, sentiment, usage, and recommendations. It\u2019s everything they need to understand how Copilot is working in our tenant.\u201d<\/p>\nAmy Ceurvorst, direct of business programs, Microsoft Digital<\/cite><\/blockquote>\n\n\n\n

At its core, Copilot controls help us manage three things:<\/p>\n\n\n\n