Smooth Google migration

Migrate from Google Drive to M365 the right way

Learn more
No items found.

Master Hacks: Migrate like a pro

Check out our video series to help you turn migration projects into masterpieces!

Watch now

Table of contents

Microsoft has been shipping fast. Some of what released recently is genuinely useful, such as Agent 365's visibility into ownerless agents, for example. Other releases are going to create real work for IT teams, like figuring out which of your Power Apps should now be exposed to Copilot and who gets to decide that.  

Let me walk you through the three things I think you need to be paying attention to right now.

1. Agents are now too numerous to govern manually

Let me start with a number that made me stop and think.

When one large organization turned on Microsoft's new Agent 365 governance tooling, they discovered 72,000 agents already running in their environment. Nobody had counted them. Nobody owned most of them. They're now adding 4,000 to 5,000 new agents every week.

Microsoft's own data shows that more than 80% of organizations are already running agents and only about 10% have any governance plan in place for them.

We've been here before, in a way. Think back to the early days of Teams or SharePoint. Creation was easy, governance lagged behind, and IT teams spent years cleaning up the mess. Agents are following the same pattern, just faster.

Manual oversight at that scale isn't realistic. That's why what Microsoft has added to Agent 365 recently matters.

What's been added

You probably already know Agent 365—Microsoft's governance layer built on Entra, Defender, Purview, and Intune. It gives admins a central registry of every agent running in the tenant.  

You can see who owns each one, what data it's accessing, and how many tool connections it has. Here’s what’s new with Agent 365

  • Agent cost management. Admins can now set hard monthly spending caps, per-user limits, and department-level Azure chargebacks. Viva Insights dashboards bring spending visibility to business and finance leaders without needing access to the M365 admin center. The framing Microsoft is pushing: manage agents like expenses, with managers approving agent spend the same way they approve a budget line.
  • Third-party agent registry. Registry Sync now pulls in agents from outside Microsoft's own tools such as Salesforce AgentForce, AWS, and Google Cloud. In other words, your agent inventory is no longer limited to what was built in Copilot Studio.
An image showing the registry sync detail view for the Amazon Bedrock connection showing options to sync, edit, and delete the connection, connection details, and a list of synced agents.

What to do

Run the audit first. Turn on Agent 365 if you haven't, see what's actually running in your tenant, and establish an ownership model. Then think about cost accountability because finance teams are going to start asking questions about agent spend and IT should have the answers ready.

2. Agents have escaped the tenant

So far, we've been talking about agents running inside your tenant—the ones built in Copilot Studio, the ones showing up in Agent 365. Those are at least visible.

But there's another layer to this that's harder to see.

Employees don't need IT approval to run an AI agent. Developer tools like GitHub Copilot CLI or Claude Code install via npm, pip, or the VS Code Marketplace—no admin rights needed. Consumer apps like OpenClaw or Claude Desktop install like any regular app. IT only finds out after the fact, when Defender scans the device. About 29% of employees are already running unsanctioned AI agents locally on their devices.

Because these tools run locally on the device, they bypass your cloud-based checkpoints entirely.

What's been added

Through Defender and Intune, Agent 365 can now continuously scan managed devices for local agent platforms like GitHub Copilot and OpenClaw, surface them in the same registry as your sanctioned tools, and block the ones you don't want via an automatically generated Intune policy.

What to do

Add shadow AI discovery to your next security review cycle. The question isn't whether your employees are using unauthorized AI tools. They are. The question is whether you have visibility into which ones, and whether you have a policy for what happens when you find them.

If your organization already uses Defender and Intune, the infrastructure is there. It just needs to be configured

Download: Quick-start checklist to reduce AI risk in M365

3. Agents can now act on every app you've ever built

Have you been building Power Apps over the years? Those apps hold real business data, like tables, forms, grids, custom controls built for specific workflows. Until now, they stayed separate from AI.

That's changed.

What's new

Microsoft shipped a new "App MCP" toggle. Switch it on for any existing Power App, and that app—its tables, forms, grids, and custom controls—becomes accessible to Copilot. Copilot can read from it and write to it. No rebuilding required.

For example, a user can now reconcile their meetings with their timesheet in one step, directly from Outlook. No more switching between apps and doing it manually.

To put all that in perspective: Microsoft has over 800,000 Power Apps running internally. Most organizations have hundreds or thousands of their own. All of that existing work can now be connected to AI without starting over.

What to do

  • Start an inventory of your existing Power Apps and decide which ones should be exposed to Copilot, and which ones shouldn’t.
  • Prioritize apps that support high-value, repetitive work, but review permissions, data sensitivity, and ownership before enabling App MCP. This should not be a maker-by-maker decision. Treat it as a governed capability with clear approval, monitoring, and rollback processes.

Get ahead of agents before they get ahead of you

Agents are useful. The ones running in your tenant, on your users' laptops, and inside your Power Apps are going to keep multiplying whether you have a governance plan or not.

My honest take: most IT teams are still treating agents as an experimentation problem, while the real issue is operational control.  

The priority now should be visibility. Build one reliable inventory of the agents, tools, owners, data access, and costs in your environment. Once you can see what exists, you can make informed decisions about what to allow, what to govern, and what to shut down.

No items found.