An autonomous agent does not fix the flaws in your tenant, it exploits them at full speed. A messy SharePoint, an overly broad share or an agent with no owner turns into answers that sound credible but are wrong, or even into data leaks. This tutorial walks you through a readiness audit built on ten signals, from agent identities to impact measurement, with a visible result at each step.
Prerequisites: licences, roles and modules to gather before you start
Gather these items before doing anything. Several security features depend on a separate licence, and it is better to know that before discovering a missing menu.
Before you start
- A Microsoft 365 tenant with Microsoft Entra ID (formerly Azure AD): Microsoft Entra Agent ID is open to all Entra customers.
- To apply conditional access, identity protection and governance to agents: Microsoft Agent 365. It is included in Microsoft 365 E7 and available as an add-on for E5, A5 and Business Premium; it is not included in E3 or E5.
- To create agents: a Copilot Studio User License ($0) plus a tenant licence, or the Copilot Studio Author role.
- For agents backed by SharePoint: a Microsoft 365 Copilot licence for users, or pay-as-you-go billing enabled on the tenant.
- Access to the Microsoft 365 admin center, the Microsoft Entra admin center and the Microsoft Purview portal, with a role that allows reading Microsoft 365 groups.
- For the script in the "Implementation" section: PowerShell and the Microsoft.Graph.Groups module.
- A spreadsheet to record a red, orange or green status for each signal.
What changed in 2026 for agent identities
Three dated changes determine where you inventory and govern your agents. They come from the Microsoft Entra "What's new" page and the Copilot Studio documentation.
April 2026
Entra Agent ID generally available
According to the Microsoft Learn documentation, this identity and authorisation platform for AI agents is built on OAuth 2.0 and on the MCP and A2A protocols.
1 May 2026
Agent 365 becomes the single registry
The "Agent registry" and "Agent collections" blades in the Entra admin center are retired. Agent 365 becomes the registry and control plane for agents, while Entra remains the identity layer.
May 2026
Automatic identity and durable sponsors
Copilot Studio creates a Microsoft Entra Agent ID for every new agent, with no way to opt out. Lifecycle Workflows, now generally available, transfer sponsorship to the manager when the sponsor leaves the organisation.
Practical consequence: an agent is now a full identity actor that you inventory, tie to an accountable human and restrict in terms of permissions, just as you would for an employee.
Licences: the cost of the control layer
The Microsoft licensing FAQ indicates that Agent 365 is billed per user. The amounts below are list prices.
99 $
Per user per month for Microsoft 365 E7, which includes Agent 365
Microsoft, licensing FAQ
15 $
Per user per month for Agent 365 as a standalone offer
Microsoft, licensing FAQ
200 $
Per month for a pack of 25,000 Copilot Studio Copilot Credits
Copilot Studio licensing guide, May 2026
Copilot Studio "messages" have become Copilot Credits, with a pay-as-you-go option. Agents published in Microsoft 365 Copilot are included for users licensed for Microsoft 365 Copilot, within reasonable usage limits.
Agent on SharePoint: the licence determines access to data
According to the Microsoft Learn documentation on Copilot extensibility costs, an agent backed by SharePoint can only be used by users who hold a Microsoft 365 Copilot licence, or in a tenant with pay-as-you-go billing. With Copilot Chat alone and no pay-as-you-go billing, the agent is limited to its instructions and public web data. Tenant data consumed by the agent is billed in Copilot Credits.
The ten signals of an environment that is not ready, in three families
None of these signals is an AI problem: they are organisational flaws that the agent makes visible, then amplifies. The table maps each signal to what to check and where to act. To understand why autonomy makes each of them worse, read our article on autonomy, the action loop and the security of an AI agent.
| Signal | What to check | Where to act |
|---|---|---|
| 1. Scattered knowledge | Orphaned SharePoint sites, abandoned Teams teams, files in personal OneDrives | SharePoint, Teams, Microsoft Graph |
| 2. Written policies and actual practices diverge | Sharing, labelling and retention actually applied | Microsoft Purview |
| 3. No real-time data | Direct connections to business systems rather than exports | Microsoft Graph connectors, Power Platform, Dataverse |
| 4. Undocumented workflows | Formalised procedures and explicit instructions | SharePoint, Power Automate, agent configuration |
| 5. Multiple versions of the truth | Reference sources, archiving of outdated versions | SharePoint, Purview lifecycle policies |
| 6. No validation of outputs | Approval steps and a return path when an output is rejected | Power Automate |
| 7. Security designed for applications | Permissions, sensitivity labels, DLP, agent identity | SharePoint, Purview, Microsoft Entra |
| 8. No impact indicators | Baseline, tracking of usage and results | Copilot dashboards, Copilot Studio analytics |
| 9. Leadership not leading by example | Visible use of the tools by managers | Change management |
| 10. No iteration after launch | One owner per agent, review of conversations and failures | Copilot Studio, Agent 365 |
Procedure: audit and fix the environment in nine steps
Take an illustration: an organisation is preparing a procurement assistant agent that relies on SharePoint sites. It works through the nine steps below before publishing. Each step ends with what you should observe to consider it successful.
Inventory existing agents
Open the Microsoft 365 admin center and go to the All agents view, which serves as the inventory now that Agent 365 is the single registry. Do not look for the "Agent registry" and "Agent collections" blades in the Entra admin center any more: they have been retired since 1 May 2026.
You should see the list of agents in the tenant. Copy it into your spreadsheet, one row per agent.
Identify the identity of each Copilot Studio agent
For each agent in the list, note its creation date. New agents automatically receive a Microsoft Entra Agent ID since May 2026. Older agents remain on app registrations until a migration planned by Microsoft, but you can migrate them yourself by following the page Entra Agent IDs for Copilot Studio agents.
Your spreadsheet should distinguish two columns: agents on Agent ID and agents to migrate.
Assign a human sponsor to each agent
For each agent identity, or each blueprint, enter an accountable human sponsor. If you use a group as sponsor, it must be a dynamic membership group or a Microsoft 365 group. Then enable the Lifecycle Workflows that transfer sponsorship to the manager when the sponsor leaves the organisation: no agent is left orphaned. Our article on the secure lifecycle of AI agents details this governance.
Each row in the spreadsheet now carries an owner's name. A row with no name is an agent to suspend.
Spot the knowledge silos
List the SharePoint sites without an owner, the abandoned Teams teams and the content stored in personal OneDrives. For Microsoft 365 groups, run the script in the "Implementation" section: it produces a CSV file of groups with no owner or no recent renewal.
You should end up with a file listing the groups to review. For each one, decide: assign an owner, archive or delete.
Designate reference sources
For each domain covered by the agent (procurement, HR, legal), choose a single authoritative location. Archive outdated versions of documents and apply lifecycle policies from the Microsoft Purview portal. In our illustration, a single SharePoint site now holds the current framework contracts and order templates.
You should be able to say, for each question the agent will handle, which single document holds the answer.
Review permissions, labels and DLP
Check the SharePoint permissions of the sites the agent will be able to read, remove excessive shares, apply sensitivity labels and verify the Microsoft Purview data loss prevention (DLP) policies. An agent inherits the permissions it is granted or those of the user it acts for: the slightest oversharing is therefore exploitable at scale. Our analysis of AI agent security beyond the model complements this point.
Test with a limited-privilege account: the agent must reveal nothing that this account cannot open itself.
Add human checkpoints
Identify the agent's sensitive actions (external sending, ordering, publishing) and insert an approval step in the corresponding Power Automate flow. Also plan a return path: what happens to a rejected output, and who is informed?
A test output must remain pending until a named human approves it.
Connect live data and document workflows
Replace periodic exports with Microsoft Graph connectors, Power Platform connectors or Dataverse sources plugged into the business systems. Then write down, in SharePoint or in the agent's instructions, the procedures that exist only in your teams' heads.
The agent must answer with up-to-date data, and every automated process must point to a written procedure.
Measure, iterate and lead by example
Record a baseline before deployment (time spent, error rate, workload), then track results with the Copilot adoption dashboards and Copilot Studio analytics. Schedule a regular review of conversations and failures, with updates to sources and instructions. Finally, ask a manager to use the agent publicly in their team: adoption follows the example set from the top.
You now have a starting value, a date for the first review and an owner for that review.
Verifying the result: the readiness grid
Verification covers the ten signals. Assign a status to each in your spreadsheet, then check these points.
Checks before going into production
- All agents in the All agents view have an identified human sponsor.
- Agents created before May 2026 are either migrated to Entra Agent ID or scheduled to be.
- The CSV file of groups to review has been processed: no more groups without an owner among the agent's sources.
- Each of the agent's domains relies on a single reference source.
- A limited-privilege account cannot get the agent to return content it is not allowed to see.
- A sensitive action does go through human approval.
- The necessary licences (Copilot or pay-as-you-go billing, Agent 365 if needed) are assigned.
- A baseline is recorded to measure impact.
Run one last revealing test: ask the agent a question whose answer is in an archived document. If the agent cites it, signal 5 stays red.
Implementation: inventory the Microsoft 365 groups to review
This script addresses signal 1 (knowledge silos) and helps prepare signal 10 (identified owner). It is read-only: it writes nothing to the tenant, so no simulation mode is needed. You can re-run it on each tenant.
- Required module:
Install-Module Microsoft.Graph.Groups -Scope CurrentUser - Minimum permission: the delegated scope
Group.Read.All. - Output: a CSV file listing Microsoft 365 groups with no owner or whose renewal date exceeds the chosen threshold.
1param(2 # Threshold in days beyond which a group is flagged3 [int]$InactiviteJours = 365,4 # Output file5 [string]$CheminCsv = '.\groupes-a-revoir.csv'6)7 8# Connexion avec le scope minimal en lecture9Connect-MgGraph -Scopes 'Group.Read.All' -NoWelcome10 11$seuil = (Get-Date).AddDays(-$InactiviteJours)12 13# Récupération des groupes Microsoft 365 (type Unified), équipes Teams incluses14$filtre = "groupTypes/any(c:c eq 'Unified')"15$groupes = Get-MgGroup -Filter $filtre -All -Property 'id,displayName,createdDateTime,renewedDateTime,visibility'16 17$resultat = foreach ($g in $groupes) {18 # Lecture des propriétaires de chaque groupe19 $proprietaires = @(Get-MgGroupOwner -GroupId $g.Id -All)20 $sansProprietaire = ($proprietaires.Count -eq 0)21 $ancien = ($g.RenewedDateTime -and $g.RenewedDateTime -lt $seuil)22 23 # On ne retient que les groupes à revoir24 if ($sansProprietaire -or $ancien) {25 [pscustomobject]@{26 Nom = $g.DisplayName27 Id = $g.Id28 Visibilite = $g.Visibility29 Creation = $g.CreatedDateTime30 Renouvellement = $g.RenewedDateTime31 SansProprietaire = $sansProprietaire32 AncienRenouv = $ancien33 }34 }35}36 37# Export pour traitement dans votre tableur38$resultat | Export-Csv -Path $CheminCsv -NoTypeInformation -Encoding UTF839Write-Host ('{0} groupe(s) à revoir, export : {1}' -f @($resultat).Count, $CheminCsv)An indicator, not proof of inactivity
The renewal date does not measure a group's real activity. Use the list as a starting point for a review with the owners, not as an automatic deletion list.
Troubleshooting
The agent answers without using your SharePoint documents
Check the user's licence. With Copilot Chat alone and no pay-as-you-go billing, the agent relies only on its instructions and on public web data. Assign a Microsoft 365 Copilot licence or enable pay-as-you-go billing on the tenant.
The script returns an authorisation error
Consent to the Group.Read.All scope is missing or your account does not have a role that allows reading groups. Re-run Connect-MgGraph -Scopes 'Group.Read.All', accept the consent or request it from an administrator, then run the script again.
You can no longer find the agent inventory in Entra
This is expected: since 1 May 2026, the "Agent registry" and "Agent collections" blades in the Entra admin center are retired. Use the All agents view in the Microsoft 365 admin center. If you are looking for governance and access controls, remember that they require Agent 365.
The group chosen as sponsor is rejected
Sponsor groups must be dynamic membership groups or Microsoft 365 groups. Replace a static security group with one of these two types.
Frequently asked questions
Do you need Agent 365 to use Microsoft Entra Agent ID?
No. Microsoft Entra Agent ID is open to all Entra customers. Agent 365 becomes necessary to extend conditional access, identity protection and governance to agents.
How much does Agent 365 cost?
According to the Microsoft licensing FAQ, billing is per user: $99 per user per month for Microsoft 365 E7, or $15 per user per month as a standalone offer (list prices). Agent 365 is not included in E3 or E5. Users who do not meet the prerequisites, for example E3 with Copilot, are not eligible.
Can you prevent Copilot Studio from creating an Entra Agent ID?
No. Since May 2026, Copilot Studio automatically creates a Microsoft Entra Agent ID for every new agent and you can no longer opt out. Previously, it created an Azure app registration.
Are my existing agents migrated automatically?
Not yet. They remain on app registrations until a migration planned by Microsoft, but you can migrate them manually.
Where to start: three decisions to make this week
The most worthwhile approach is to spot your two or three reddest signals and make them your first workstreams. Start with these actions.
Next actions
- Export the list of agents from the All agents view and name a sponsor for each one.
- Run the group inventory script and schedule the review with the owners.
- Test an agent with a limited-privilege account before any publication.
If your organisation is on E3 or E5 without Agent 365, start with the steps that require no additional licence: cleaning up sources, permissions, human approvals and measurement. Then assess Agent 365 based on the number of agents actually in production, not the number of potential licences.
Going further
- What is Microsoft Entra Agent ID?: agent identities, blueprints, licence prerequisites and third-party agents.
- Entra Agent IDs for Copilot Studio agents: automatic identity creation and migration of existing agents.
- Govern AI agent identities and access the same way you govern your employees: feedback from the Entra teams on access packages, sponsors and permission drift.
- Entra security for AI overview: agent sprawl and the Entra controls to address it.
- Plan Licensing and Cost for Microsoft 365 Copilot Extensibility: agent costs and licences depending on the user's licence.



