Govern Agent Lifecycle
Decide which agents are allowed, who owns them, what tools they can call, and which governance and compliance policies apply — establishing consistent guardrails across the agent lifecycle from onboarding through retirement.
Core capabilities
-
Set the tenant onboarding posture — allowed agent types, sharing, user access, availability scope, and the request-to-publish gate — so agents enter through a controlled front door
-
Approve, block, delete, start or stop, and reassign owners for agents, and automate these lifecycle actions with conditions-based rules
-
Control which tools and MCP servers agents can call tenant-wide, allowing or blocking each through the Agent 365 tooling gateway
-
Apply bundled Entra, Purview, SharePoint, and Defender policies to agents through templates so governance and compliance are enforced consistently
Supporting capabilities 5
-
Delegate agent governance least-privilege — AI Administrator to operate the estate, AI Reader for read-only oversight — while deeper Entra, Purview, and Defender controls stay with their workload roles
-
Manage, block, or delete individual agent instances — each with its own mailbox, OneDrive, and license — for fine-grained lifecycle control below the agent level
-
Evaluate and improve compliance for agents against AI regulations using ready-to-use assessments in Compliance Manager
-
Detect and investigate inappropriate or risky agent interactions to meet conduct and regulatory obligations
-
Retain and delete agent prompts and responses using Purview retention policies to meet compliance and data-minimization requirements