Agent Distribution and Supply Chain
Govern how agents — Microsoft-built, partner-built, and organization-built — become available to users, and judge how much to trust an agent your organization did not build.
Every agent a user can reach is part of your attack surface, whether it was built in-house, bought from a partner, or installed from the store. Governing distribution is two jobs at once: deciding who in the tenant can get which agents, and deciding how much to trust an agent you did not build. The Microsoft 365 admin center handles the first — approval gates, availability scoping, and a tenant-wide block — while the Microsoft 365 App Compliance Program supplies the trust signals, from self-declared Publisher Attestation to independently audited Microsoft 365 Certification.
How to address Agent Distribution and Supply Chain
-
Govern Agent Distribution
Control how agents reach users and how much to trust an agent you did not build — judge third-party trust signals, gate org-built agents through approval, scope who gets which agents, and block the ones that should not be there.
Control coverage
Governance3
Organisational and technical controls for managing the lifecycle of AI models, agents, and workloads — including inventory, policy, and accountability frameworks.
Compliance2
Controls that help organisations meet regulatory and policy obligations for AI systems, including audit trails, data residency, and policy enforcement.
Supply Chain2
Controls that protect the integrity of AI model supply chains — covering model provenance, dependency vetting, third-party plugin and connector risk, and safeguards against tampered or poisoned models and training data.
Agent Security1
Controls that secure AI agents, their tools, plugins, and external connections — including MCP server trust boundaries, tool permission scoping, prompt injection defences, and runtime behaviour constraints for autonomous and assistive agents.
Discovery1
Capabilities for discovering and inventorying AI assets, workloads, shadow AI usage, connected applications, and data sources — providing visibility as the foundation for securing what you can see.
Identity & Access1
Controls that ensure only authenticated and authorized principals can access AI models, APIs, data pipelines, and management planes.
Incident Response1
Capabilities that support detection, investigation, containment, and recovery for security incidents involving AI workloads — including automated response playbooks, forensic telemetry, and remediation guidance.
Monitoring1
Continuous observability of AI workload behaviour, usage, and anomalies through logging, metrics, and alerting — enabling detection of drift, misuse, and security events.