Microsoft 365 Admin Center
Web-based administration portal for managing users, services, security settings, and AI governance across a Microsoft 365 organization.
Capabilities
- Advanced Agent Usage InsightsObserve Agents
Provides advanced agent analytics and telemetry in the Microsoft 365 admin center — agents by creator and platform, active users over time, trending agents, agent run-time, and a per-agent Activity tab showing sessions and exceptions. Requires the Microsoft Agent 365 license.
- Agent 365 ObservabilityObserve Agents
Copilot Studio agents automatically emit OpenTelemetry telemetry — agent invocations and tool calls — to the Agent 365 observability backend without SDK instrumentation. This telemetry feeds the Microsoft 365 admin center, Microsoft Defender, and Microsoft Purview, forming the activity backbone for agent monitoring, threat detection, and compliance.
- Agent Governance ActionsGovernSecure Agents Users
Enforces the full agent lifecycle from the Agent Registry in the Microsoft 365 admin center — approving or rejecting org-built agents before they publish, scoping which users or groups each agent is deployed to, and installing, blocking, deleting, starting or stopping, reassigning owners, and publishing agents. Reduces the risk of ungoverned, overshared, or non-compliant agents by giving one place to gate, scope, and kill agents. The core actions are included with a Microsoft 365 Copilot subscription; automating them with conditions-based rules requires the Microsoft Agent 365 license.
- Agent Instance ManagementGovern Agents
Manages the individual instances created from an Agent 365 template agent (AI teammate) in the Microsoft 365 admin center — blocking, deleting, licensing, and reviewing the security and compliance of each instance, including its own OneDrive and Outlook data.
- Agent Management RolesGovern Agents
Controls who can view and govern the agent estate in the Microsoft 365 admin center through Microsoft Entra admin roles — AI Administrator and Global Administrator can install, approve, and manage agents, while AI Reader and other roles get read-only visibility.
- Agent MapObserve Agents
Visualizes the tenant's agent estate in the Microsoft 365 admin center, grouping agents by the platform that built them and surfacing clusters, relationships, and filters such as ownerless agents so administrators can interpret large agent populations at a glance. Requires the Microsoft Agent 365 license.
- Agent RegistryObserveGovern Agents
Provides a centralized inventory of every agent in the tenant — including agents built by the organization, Microsoft, and partners across Copilot Studio, Foundry, SharePoint, and connected platforms — serving as the source of truth for agent discovery, ownership, and governance in the Microsoft 365 admin center. Included with a Microsoft 365 Copilot subscription.
- Agent Registry Graph APIObserveGovern Agents
Gives administrators programmatic access to the agent registry and agent details through Microsoft Graph, so they can retrieve the full agent inventory and per-agent metadata to automate bulk agent management, onboarding, and governance. Currently in preview and requires the AI Administrator or Global Administrator role.
- Basic Agent Usage InsightsObserve Agents
Reports active users and agent usage for agents used in Microsoft 365 Copilot Chat and Microsoft 365 apps, covering declarative, SharePoint, and custom engine agents built by the organization, Microsoft, and partners. Included with a Microsoft 365 Copilot subscription.
- Copilot Security DashboardObserveGovern Users Data
Surfaces Microsoft 365 Copilot data-security posture in the Microsoft 365 admin center — data loss prevention, oversharing, and compliance insights — so administrators can monitor and act on Copilot data risk in one place. Draws on Microsoft Purview signals to give a single view of Copilot data governance.
- Copilot Web Grounding ControlsGovernSecure Users Agents
Governs whether Microsoft 365 Copilot and Copilot Chat can ground responses on the public web, and which external domains are off-limits. Admins turn web grounding on or off tenant-wide with the Allow web search in Copilot policy and exclude up to 1,000 domains, keeping untrusted or non-compliant web sources out of AI responses.
- Onboarding ControlsGovern Agents
Sets the tenant-wide onboarding posture for agents in the Microsoft 365 admin center — which agent types users can install, who can share agents, which users or groups can access them, and the security templates and rules applied to new agents.
- Policy TemplatesGovern Agents
Bundle predefined governance and security policies from Microsoft Entra, Purview, SharePoint Online, and Defender into templates that administrators apply to agents in the Microsoft 365 admin center, standardizing controls and reducing manual configuration across the agent estate. Requires the Microsoft Agent 365 license.
- Registry SyncObserveGovern Agents
Connects external AI agent platforms — Amazon Bedrock, Google Vertex AI, Salesforce Agentforce, and Databricks Genie — and synchronizes their agents into the Microsoft 365 agent registry for centralized visibility and governance. In preview and requires the Microsoft Agent 365 license.
- Shadow AI Agent Detection and GovernanceObserveGovern Endpoints
Detects and blocks unmanaged AI agents — including local MCP servers, agentic CLIs, and unauthorized coding assistants — on managed Windows devices by pushing Intune enforcement policies directly from the Microsoft 365 admin center. Currently in public preview; detection and blocking support is available for OpenClaw.
- Tool ControlsGovern Agents
Gives administrators centralized control in the Microsoft 365 admin center over which tools and Model Context Protocol (MCP) servers agents can access tenant-wide — Microsoft-provided Work IQ MCP servers and customer-registered Bring Your Own (BYO) MCP servers. Requires the Microsoft Agent 365 license.