# How to govern AI agents across Microsoft

> Start with one agent that matters. Name its business owner, open the records your team already trusts, and ask what it is, what it can reach, what it has done, who may approve a change, and how you will verify the result. Microsoft spreads those answers across several truthful but partial systems, so keep the evidence joined without pretending one screen knows everything.

- Author: [Celest](https://celest.dev/)
- Published: 2026-07-27
- Last materially updated: 2026-07-27
- Evidence level: Primary-source operating guide
- Canonical URL: https://celest.dev/learn/microsoft/agent-governance
- MCP endpoint: https://celest.dev/learn/microsoft/agent-governance/mcp
- Source revision: `sha256:edaa745a9821303d912cc28faa8fdfcec0541d9bece3843c9f7a0ed9120d0dc7`

**Scope:** This is a practical operating guide for workplace teams reviewing agents across Microsoft 365, Copilot Studio, Power Platform, Entra, Azure, and adjacent GitHub workflows. It explains where evidence may live and how to make an accountable decision; it is not a Microsoft product catalog, certification standard, or claim that every source is available in every tenant.

## Start with one agent on Monday morning

You do not need to solve the whole estate before doing useful governance. Choose an agent people rely on, bring together the person accountable for the work and the person who understands the platform, and leave the session with one honest result and one named next step.

- Choose one agent tied to real work, important data, or a decision your team cares about.
- Name a business owner and a platform owner. One person may fill both roles, but the responsibilities are different.
- Open the source records you already trust. Record when each source was checked and whether it answered the question.
- Write down what is confirmed, what needs attention, what remains unknown, who acts next, and how the team will check the result.

> **The useful unit of progress:** One agent. One owner. One unanswered question. One next step.

## Where to look in Microsoft

No single portal answers every governance question. Start with the row that matches the question in front of you, then keep the source and observation time attached to the answer.

_A practical map of Microsoft agent evidence_

| Question | Start here | What it can establish—and what it cannot |
| --- | --- | --- |
| What agents exist? | Microsoft 365 admin center: Agent Registry and Agent Map | Visible inventory, ownership gaps, and lifecycle posture. It is a front door, not proof that every agent or relevant record is present. [[agent-365-overview]](#source-agent-365-overview) [[agent-registry]](#source-agent-registry) [[agent-roles]](#source-agent-roles) |
| Who owns it, and what access does it have? | Microsoft Entra | Technical owner, business sponsor, permissions, sign-ins, risk, and access policy. It does not establish whether the agent is useful or behaving well. [[entra-agent-identities]](#source-entra-agent-identities) |
| What can it reach? | Copilot Studio and Power Platform | Environment, tools, connectors, knowledge, connections, sharing, and data policy. Configuration shows potential reach, not what happened in one run. [[copilot-environments]](#source-copilot-environments) [[power-platform-data-policy]](#source-power-platform-data-policy) |
| What has it done? | Copilot Studio analytics and Microsoft Purview | Operational usage and an auditable interaction record, with different coverage and retention. A gap in one source is not proof of non-use. [[copilot-analytics]](#source-copilot-analytics) [[purview-copilot-audit]](#source-purview-copilot-audit) |
| What is risky right now? | Microsoft Defender | Supported posture, recommendations, alerts, protection, and investigation. Unsupported tools or integrations remain outside that evidence. [[defender-agent-inventory]](#source-defender-agent-inventory) |
| How did it run in an engineering workflow? | Microsoft Foundry tracing or GitHub AI controls, when applicable | Run-level traces or coding-agent policy and activity. Neither replaces tenant ownership, identity, or business-purpose evidence. [[foundry-agent-tracing]](#source-foundry-agent-tracing) [[github-ai-controls]](#source-github-ai-controls) |

## Join the records without erasing their limits

Two admin screens can both be correct while answering different questions. Bring their records together, but keep four things attached to every answer: where it came from, when it was observed, whether the source was healthy, and whether another source disagreed.

> **Unknown is useful:** If no healthy source answered, keep the result unknown. That identifies an access, telemetry, ownership, or identity problem to fix; it does not prove the agent is safe, unused, ownerless, or healthy.

## Choose one honest next step

- Confirmed: record the evidence and choose when this agent should be reviewed again.
- Needs attention: name the owner and prepare one bounded proposal for the person who owns the affected boundary.
- Unknown: repair the missing access, telemetry, ownership record, or identity join before making a stronger claim.

> **Permission is not proof:** Approval means go ahead; a handoff means work crossed a boundary. Check the authoritative Microsoft source again before calling an outcome verified.

## What Celest does today

Celest's intended first offering is a fixed-scope, read-only Agent Estate Review. Current product proof covers bounded development work for collection and deterministic diagnosis; populated live-review delivery remains staged work. The Microsoft-facing Estate Review API does not publish, deploy, assign, activate, block, delete, change permissions, or otherwise mutate the tenant, and fresh provider-side verification after external execution remains future work.

> **Bring this to a first review:** One agent, the people who own its work and platform, one unanswered question, and access to the source your team already trusts.

## Limitations

- Microsoft product names, portal locations, roles, licensing, and source coverage change. Confirm the current boundary in your own tenant before treating a record as authoritative.
- No source listed here is guaranteed to cover every agent type, tool, runtime, or interaction. Preview and integration-specific coverage must remain labeled.
- Analytics, audit, security, and platform traces have different retention windows and semantics. Missing data in one source does not prove inactivity or safety.
- This operating guide is not legal advice, a security certification, or a universal compliance checklist. Each organization must choose authorities, thresholds, and required evidence appropriate to its work.

## Sources

<a id="source-agent-365-overview"></a>1. [Microsoft Agent 365 overview](https://learn.microsoft.com/en-us/microsoft-agent-365/overview) — Microsoft Learn. Accessed 2026-07-27. Microsoft's current framing of Agent 365 as a control plane spanning agent registry, identity, security, governance, and interoperability.
<a id="source-agent-registry"></a>2. [Manage agents in the Microsoft 365 admin center](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-registry?view=o365-worldwide) — Microsoft Learn. Accessed 2026-07-27. The centralized Agent Registry, ownership and unmanaged-agent views, and the boundary between central and product-specific controls.
<a id="source-agent-roles"></a>3. [Roles and permissions for managing agents](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/agent-roles-perms?view=o365-worldwide) — Microsoft Learn. Accessed 2026-07-27. Tenant-wide and product-specific administrative authority for Microsoft agent governance surfaces.
<a id="source-entra-agent-identities"></a>4. [Manage agent identities in the Microsoft Entra admin center](https://learn.microsoft.com/en-us/entra/agent-id/manage-agent-identities-admin) — Microsoft Learn. Accessed 2026-07-27. Agent identity records, technical owners, business sponsors, permissions, sign-ins, and identity lifecycle administration.
<a id="source-copilot-environments"></a>5. [Work with Power Platform environments in Copilot Studio](https://learn.microsoft.com/en-us/microsoft-copilot-studio/environments-first-run-experience) — Microsoft Learn. Accessed 2026-07-27. The Power Platform environment boundary for Copilot Studio agents, resources, security, and governance.
<a id="source-power-platform-data-policy"></a>6. [Data policies in Power Platform](https://learn.microsoft.com/en-us/power-platform/admin/wp-data-loss-prevention) — Microsoft Learn. Accessed 2026-07-27. Connector and data-policy controls applied to Power Platform and Copilot Studio capabilities.
<a id="source-copilot-analytics"></a>7. [Analyze agent performance and usage](https://learn.microsoft.com/en-us/microsoft-copilot-studio/analytics-overview) — Microsoft Learn. Accessed 2026-07-27. Copilot Studio activity, quality, tool, trigger, and knowledge analytics plus documented retention limits.
<a id="source-purview-copilot-audit"></a>8. [Audit Copilot and AI application activity](https://learn.microsoft.com/en-us/purview/audit-copilot) — Microsoft Learn. Accessed 2026-07-27. Microsoft Purview audit records for Copilot and AI application interactions and referenced resources.
<a id="source-defender-agent-inventory"></a>9. [AI agent inventory in Microsoft Defender](https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-inventory) — Microsoft Learn. Accessed 2026-07-27. Defender's agent inventory, risk, recommendations, alerts, tools, identities, and investigation boundary.
<a id="source-foundry-agent-tracing"></a>10. [Set up tracing for AI agents in Microsoft Foundry](https://learn.microsoft.com/en-us/azure/foundry/observability/how-to/trace-agent-setup) — Microsoft Learn. Accessed 2026-07-27. Opt-in run-level tracing and Application Insights prerequisites for agents hosted in Microsoft Foundry.
<a id="source-github-ai-controls"></a>11. [Enterprise policies and features for GitHub Copilot](https://docs.github.com/en/copilot/concepts/policies) — GitHub Docs. Accessed 2026-07-27. The enterprise policy boundary for Copilot features, models, and coding-agent availability in GitHub.
