Skip to content
Practitioner playbookVerified October 2026

Microsoft AI Security and Governance Playbook: Copilot and Agents

A practitioner playbook for securing and governing Microsoft 365 Copilot, Copilot Studio and Foundry agents. Every control mapped to ISO/IEC 42001, the EU AI Act and NIST AI RMF, with licence signals and the evidence it produces.

By Krish Pasumarthi, Founder, CybrGenCRISC, CDPSE, ISO/IEC 42001 Lead Auditor

controls
18controls
lifecycle stages
6lifecycle stages
frameworks mapped
3frameworks mapped
regional overlays
4regional overlays

How to read each control

Decision trigger
The signal that tells you to switch this on now.
Licence signal
What gates it commercially, as published in October 2026.
Evidence produced
The artefact an auditor or regulator will accept.
Framework mapping
Where the control lands in ISO/IEC 42001, the EU AI Act and NIST AI RMF.
Watch out
The mistake we see most often in real tenants.

Microsoft changes product names, preview status and licensing frequently. Treat licence and status signals as a dated snapshot, confirm against Microsoft Learn and your licensing agreement before you commit, and note that list prices are in USD and vary by region and agreement.

Stage 01

1. Discover

What AI is running, who owns it, and what data does it touch?

You cannot govern what you cannot see. Start with one inventory of AI apps and agents, then reconcile it against the shadow AI your people already use.

PurviewGA: Generally available

Purview Data Security Posture Management (AI observability)

  • Microsoft 365 Copilot
  • Copilot Studio agents
  • Foundry and custom AI apps
  • Third-party AI apps

The current DSPM replaces the classic DSPM for AI and adds an inventory of AI apps and agents with activity in the last 30 days, how many are high risk, and how many had sensitive interactions.

Decision trigger
Turn on before the first Copilot pilot. You need a baseline of AI usage and sensitive interactions before you can show any control is working.
Licence signal
Classic DSPM for AI: Microsoft 365 E5 or E5 Compliance. AI observability and Insider Risk for agents: Microsoft 365 E7 or Agent 365 (generally available from mid-2026).
Evidence produced
  • AI app and agent inventory with risk ratings
  • Activity explorer records of AI interactions
  • Recommended policy set and its adoption status
Framework mapping

ISO/IEC 42001

  • A.4.2 Resource documentation
  • A.6.2.6 Operation and monitoring

EU AI Act

  • Art. 26(5) Deployer monitoring

NIST AI RMF

  • GOVERN 1.6 AI inventory
  • MANAGE 4.1 Post-deployment monitoring
Watch out

Make sure you are in the current DSPM, not the classic view. Agent 365 visibility only appears on the AI observability page of the current version.

Microsoft Learn (opens in a new tab)

DefenderMixed: Core GA, newer agent features in preview

Shadow AI discovery and access control

  • Third-party AI apps

Defender for Cloud Apps discovers and risk-rates generative AI apps in use. Entra Internet Access adds granular network controls for generative AI apps, and the Purview browser extension and Edge for Business add inline data protection in the browser.

Decision trigger
Use when staff are already using public AI tools and you need to sanction, monitor or block them rather than pretend usage is zero.
Licence signal
Defender for Cloud Apps is in Microsoft 365 E5. Entra Internet Access is part of the Microsoft Entra Suite (included in E7 or as an add-on).
Evidence produced
  • Sanctioned and unsanctioned AI app register
  • Block and monitor policies with hit counts
  • Browser DLP events for AI sites
Framework mapping

ISO/IEC 42001

  • A.9.2 Processes for responsible use
  • A.10.3 Suppliers

EU AI Act

  • Art. 26(1) Use in line with instructions

NIST AI RMF

  • GOVERN 1.6 AI inventory
  • GOVERN 6.1 Third-party AI risk policies
Watch out

Blocking everything drives usage to personal devices. Pair any block with a sanctioned alternative and a published AI acceptable use policy.

Microsoft Learn (opens in a new tab)

Agent 365GA: Generally available

Agent 365 control plane and Entra Agent Registry

  • Microsoft 365 Copilot
  • Copilot Studio agents
  • Foundry and custom AI apps
  • Third-party AI apps

Agent 365 is Microsoft's control plane for deploying, organising and governing agents. Each agent gets an Entra Agent ID, and the Entra Agent Registry inventories Microsoft and third-party agents in one place.

Decision trigger
Adopt once agents act on behalf of users or run autonomously, or when security needs one inventory across Copilot Studio, Foundry and third-party builders.
Licence signal
Generally available since 1 May 2026. USD 15 per user per month standalone, or included in Microsoft 365 E7. Licensed per user; agents acting on behalf of a licensed user are covered.
Evidence produced
  • Agent register with owner, identity and status
  • Agent lifecycle actions (approve, block, retire)
  • Agent activity in the unified audit log
Framework mapping

ISO/IEC 42001

  • A.3.2 AI roles and responsibilities
  • A.4.2 Resource documentation

EU AI Act

  • Art. 14 Human oversight
  • Art. 26(2) Assigned oversight

NIST AI RMF

  • GOVERN 1.6 AI inventory
  • MANAGE 2.4 Deactivate or disengage
Watch out

Agent 365 is now the licensing gate for several agent controls across Entra, Defender and Purview. Some capabilities were still in preview at general availability, so check feature status before you promise outcomes.

Microsoft Learn (opens in a new tab)

Stage 02

2. Protect data

Can AI reach data it should not, and can sensitive data leave through a prompt?

Copilot surfaces what users can already access. Most Copilot risk is a permissions and labelling problem that AI makes visible, so fix exposure before you scale licences.

SharePointGA: Generally available

SharePoint Advanced Management oversharing controls

  • Microsoft 365 Copilot
  • Copilot Studio agents

Oversharing assessment, Restricted Access Control (limit a site to security groups) and Restricted Content Discovery (keep a site out of Copilot and org-wide search without changing permissions).

Decision trigger
Run the oversharing baseline before broad Copilot rollout, and again whenever a business-critical site is created or merged.
Licence signal
Included once a tenant assigns at least one Microsoft 365 Copilot licence. Restricted site creation by apps still needs the SharePoint Advanced Management Plan 1 add-on.
Evidence produced
  • Oversharing baseline report and remediation log
  • Sites under Restricted Access Control or Restricted Content Discovery
  • Site access review outcomes
Framework mapping

ISO/IEC 42001

  • A.7.2 Data for AI systems
  • A.9.2 Processes for responsible use

EU AI Act

  • Art. 26(4) Relevance of input data

NIST AI RMF

  • MEASURE 2.10 Privacy risk
  • MANAGE 1.3 Responses to priority risks
Watch out

Restricted Content Discovery hides content; it does not fix permissions. Microsoft warns that overuse degrades search and Copilot answer quality, so treat it as a stopgap while access is cleaned up.

Microsoft Learn (opens in a new tab)

PurviewGA: Generally available

Sensitivity labels and label-based Copilot exclusion

  • Microsoft 365 Copilot

A DLP policy on the Microsoft 365 Copilot and Copilot Chat location can stop Copilot using files and emails with specific sensitivity labels for summarisation and grounding.

Decision trigger
Use when you hold material that must never be summarised by AI, such as board papers, legal privilege, M&A or highly classified records.
Licence signal
Manual labelling is broadly available. Automatic labelling and advanced classification need Microsoft 365 E5 or E5 Compliance.
Evidence produced
  • Label taxonomy and label coverage metrics
  • DLP policy scoped to the Copilot location
  • Policy match reports
Framework mapping

ISO/IEC 42001

  • A.7.2 Data for AI systems
  • A.7.5 Data provenance

EU AI Act

  • Art. 26(4) Relevance of input data

NIST AI RMF

  • MEASURE 2.10 Privacy risk
  • MANAGE 1.3 Responses to priority risks
Watch out

Label-based exclusion only protects what is labelled. Low label coverage gives false comfort, so measure coverage before you report this control as effective.

Microsoft Learn (opens in a new tab)

PurviewMixed: Core GA, newer agent features in preview

DLP for Microsoft 365 Copilot prompts

  • Microsoft 365 Copilot
  • Copilot Studio agents

Real-time DLP that stops Copilot and Copilot Chat responding when a prompt contains selected sensitive information types, including custom ones, and stops that data being used for Graph or web grounding. A newer action blocks only external web search while still answering from internal content.

Decision trigger
Switch on when Copilot is live for any population that handles regulated identifiers, payment data or client-confidential information.
Licence signal
Microsoft's rollout notice scoped it to tenants with Microsoft 365 Copilot (free and paid), including E1, E3 and E5. Prompt blocking became generally available around April 2026; web-search restriction was in preview.
Evidence produced
  • DLP policy on the Copilot location, simulation then enforcement
  • DLP incident reports for blocked prompts
  • Tuning log for custom sensitive information types
Framework mapping

ISO/IEC 42001

  • A.9.2 Processes for responsible use
  • A.7.2 Data for AI systems

EU AI Act

  • Art. 26(1) Use in line with instructions

NIST AI RMF

  • MEASURE 2.10 Privacy risk
  • MANAGE 1.3 Responses to priority risks
Watch out

Start in simulation mode. Turning on block for every sensitive information type on day one creates false positives and user workarounds. Enforce the two or three highest-impact types first.

Microsoft Learn (opens in a new tab)

Stage 03

3. Identity and access for agents

Does every agent have an identity, an accountable owner and least-privilege access?

Agents are now first-class identities. Treat them like privileged workloads: named sponsor, scoped access, risk-based blocking and a way to switch them off.

EntraGA: Generally available

Entra Agent ID and agent lifecycle governance

  • Copilot Studio agents
  • Foundry and custom AI apps
  • Third-party AI apps

Purpose-built identities and OAuth flows for agents, with migration paths for Copilot Studio agents and custom app registrations. Entra ID Governance extends lifecycle and access management to agent identities.

Decision trigger
Use for every agent that calls APIs or reads business data. Shared service principals and personal maker credentials are not acceptable agent identities.
Licence signal
Agent ID is generally available. Lifecycle and access reviews rely on Entra ID Governance capabilities; confirm your entitlement.
Evidence produced
  • Agent identities with named sponsor or owner
  • Access reviews for agent permissions
  • Joiner, mover, leaver records for agents
Framework mapping

ISO/IEC 42001

  • A.3.2 AI roles and responsibilities
  • A.6.2.5 Deployment

EU AI Act

  • Art. 14 Human oversight
  • Art. 15 Cybersecurity

NIST AI RMF

  • GOVERN 2.1 Roles and responsibilities
  • MEASURE 2.7 Security and resilience
Watch out

Migrating existing Copilot Studio agents to Agent ID is a project, not a toggle. Inventory first, then migrate highest-privilege agents first.

Microsoft Learn (opens in a new tab)

EntraMixed: Core GA, newer agent features in preview

Conditional Access and ID Protection for agents

  • Copilot Studio agents
  • Foundry and custom AI apps
  • Third-party AI apps

Conditional Access policies that target agent identities and agent user accounts, with templates to block high-risk agents and to govern autonomous and on-behalf-of access. ID Protection supplies agent risk.

Decision trigger
Use as the kill switch: block high-risk agents automatically and restrict autonomous agents to the resources they were approved for.
Licence signal
Microsoft added dedicated service plans for these capabilities to Agent 365 and Microsoft 365 E7. Tenants using them without either licence will need one to continue.
Evidence produced
  • Conditional Access policies scoped to agents
  • Agent sign-in logs with policy evaluation
  • Agent risk detections and remediation
Framework mapping

ISO/IEC 42001

  • A.6.2.6 Operation and monitoring

EU AI Act

  • Art. 15 Cybersecurity

NIST AI RMF

  • MEASURE 2.7 Security and resilience
  • MANAGE 2.4 Deactivate or disengage
Watch out

Agents cannot do MFA or device compliance, so conditions and grant controls are narrower than for people. Agent identities and agent user accounts are separate targets: a policy scoped to one does not protect the other.

Microsoft Learn (opens in a new tab)

Power PlatformGA: Generally available

Copilot Studio environments, connector DLP and agent inventory

  • Copilot Studio agents

Power Platform environment strategy, Managed Environments and connector DLP policies constrain what makers can build and publish. The Power Platform admin center inventory lists Copilot Studio and Agent Builder agents with owners and connectors.

Decision trigger
Use the moment makers outside IT can create agents. Default and personal environments are where shadow agents appear.
Licence signal
Inventory is in the Power Platform admin center. Managed Environments availability depends on Power Platform licensing.
Evidence produced
  • Environment strategy and routing rules
  • Connector classification and DLP policies
  • Agent inventory export with owners and connectors
Framework mapping

ISO/IEC 42001

  • A.6.1.3 Processes for responsible design and development
  • A.6.2.5 Deployment

EU AI Act

  • Art. 26(1) Use in line with instructions

NIST AI RMF

  • GOVERN 1.6 AI inventory
  • MAP 4.1 Third-party component risk
Watch out

No agent should publish to Teams or Microsoft 365 Copilot straight from a maker environment. Require a promotion path with review.

Microsoft Learn (opens in a new tab)

Stage 04

4. Build safely

Are custom agents and AI apps tested and guarded before they reach users?

For anything built in Foundry or with custom code, guardrails and evaluations are the release gate. Posture management keeps the configuration honest after go-live.

FoundryGA: Generally available

Foundry guardrails and Prompt Shields

  • Foundry and custom AI apps

Configurable guardrails for models and agents covering harmful content, groundedness and protected material, with Prompt Shields for both direct user prompt attacks and indirect attacks hidden in grounding data or tool output.

Decision trigger
Mandatory for any agent that reads external content, emails or documents it did not author, because that is where indirect prompt injection arrives.
Licence signal
Azure consumption through Azure AI Content Safety and Foundry.
Evidence produced
  • Guardrail configuration assigned per agent or model
  • Blocked and annotated events
  • Guardrail test results from the playground or API
Framework mapping

ISO/IEC 42001

  • A.6.1.3 Processes for responsible design and development
  • A.6.2.6 Operation and monitoring

EU AI Act

  • Art. 15 Accuracy, robustness and cybersecurity

NIST AI RMF

  • MEASURE 2.7 Security and resilience
  • MANAGE 1.3 Responses to priority risks
Watch out

Confirm which guardrail is actually in force at agent level versus model deployment level; do not assume they merge. Guardrails filter content, they do not replace business authorisation on tools.

Microsoft Learn (opens in a new tab)

FoundryMixed: Core GA, newer agent features in preview

Foundry evaluations and AI red teaming

  • Foundry and custom AI apps

Built-in and custom evaluators for quality, safety and task adherence, scheduled or continuous evaluation on live traces, and automated red-team scans of agents. Foundry evaluation integrates with Purview and with third-party governance platforms.

Decision trigger
Make evaluation results a release gate. No agent goes to production without a passed evaluation and red-team run against a defined threshold.
Licence signal
Azure consumption for evaluation runs and underlying model calls.
Evidence produced
  • Evaluation datasets and scored results per release
  • Red-team scan reports and remediation
  • Release approval tied to thresholds
Framework mapping

ISO/IEC 42001

  • A.6.2.4 Verification and validation
  • A.6.2.7 Technical documentation

EU AI Act

  • Art. 9 Risk management (testing)
  • Art. 15 Accuracy and robustness

NIST AI RMF

  • MEASURE 2.5 Validity and reliability
  • MEASURE 2.7 Security and resilience
Watch out

A one-off pre-launch test is not monitoring. Schedule evaluations so model or prompt changes cannot silently degrade safety.

Microsoft Learn (opens in a new tab)

PurviewMixed: Core GA, newer agent features in preview

Purview protections for custom AI apps

  • Foundry and custom AI apps
  • Third-party AI apps

The Purview SDK and native Foundry integration extend classification, DLP, audit and retention to AI apps and agents you build, so custom apps produce the same evidence as Microsoft 365 Copilot.

Decision trigger
Use when a custom AI app processes personal or confidential data and must sit inside the same audit and retention regime as the rest of the tenant.
Licence signal
Charges depend on which Purview protections you apply; confirm current pay-as-you-go terms for non-Microsoft AI.
Evidence produced
  • Prompt and response records for custom apps
  • DLP and label enforcement on custom app data
  • Retention coverage for custom AI interactions
Framework mapping

ISO/IEC 42001

  • A.6.2.8 Recording of event logs
  • A.7.2 Data for AI systems

EU AI Act

  • Art. 12 Record-keeping
  • Art. 26(6) Deployer log retention

NIST AI RMF

  • MEASURE 2.10 Privacy risk
  • MANAGE 4.1 Post-deployment monitoring
Watch out

Decide early which custom apps are in scope. Retrofitting logging after go-live means a gap in your record that you cannot backfill.

Microsoft Learn (opens in a new tab)

DefenderMixed: Core GA, newer agent features in preview

Defender for Cloud AI security posture management

  • Foundry and custom AI apps
  • Copilot Studio agents
  • Third-party AI apps

Part of the Defender CSPM plan. Discovers the AI bill of materials across Azure OpenAI, Foundry, Azure Machine Learning, Amazon Bedrock and Google Vertex AI, flags misconfigurations and vulnerable AI libraries, and maps attack paths to AI workloads.

Decision trigger
Use when AI workloads run in your own cloud subscriptions, especially across more than one cloud.
Licence signal
Defender CSPM plan. Since 1 July 2026, agent discovery and posture for Foundry agents and third-party cloud agents also require Agent 365.
Evidence produced
  • AI bill of materials
  • AI security recommendations and remediation status
  • Attack path analysis for AI workloads
Framework mapping

ISO/IEC 42001

  • A.4.4 Tooling resources
  • A.6.2.6 Operation and monitoring

EU AI Act

  • Art. 15 Cybersecurity

NIST AI RMF

  • MEASURE 2.7 Security and resilience
  • MAP 4.1 Third-party component risk
Watch out

Enabling Defender CSPM alone no longer covers agent posture. Check the Agent 365 dependency before you scope a Defender rollout.

Microsoft Learn (opens in a new tab)

Stage 05

5. Detect and respond

Will you know when an agent is attacked or a user misuses AI?

Prompt injection, data exfiltration through AI and inappropriate use need detection that feeds your existing SOC, not a separate console nobody watches.

DefenderMixed: Core GA, newer agent features in preview

Defender threat protection for AI services and agents

  • Foundry and custom AI apps
  • Copilot Studio agents

Runtime detection of AI-specific attacks such as direct and indirect prompt injection and data exfiltration attempts, with alerts correlated in Defender XDR and Sentinel and hunting across Copilot Studio and Foundry logs.

Decision trigger
Use once an AI app or agent is internet-facing or can take actions, so the SOC sees AI attacks in the same queue as everything else.
Licence signal
Defender for Cloud plan billing for AI services. Threat protection for Copilot Studio agents entered preview in late 2025; confirm current status for Foundry agents.
Evidence produced
  • AI threat alerts and incident records
  • SOC playbooks covering AI incidents
  • Hunting queries over agent activity
Framework mapping

ISO/IEC 42001

  • A.6.2.6 Operation and monitoring
  • A.8.4 Communication of incidents

EU AI Act

  • Art. 15 Cybersecurity
  • Art. 26(5) Inform provider of serious incidents

NIST AI RMF

  • MANAGE 4.1 Post-deployment monitoring
  • MANAGE 4.3 Incident communication
Watch out

Alerts without a runbook are noise. Write the AI incident playbook, including who can disable an agent, before you switch detection on.

Microsoft Learn (opens in a new tab)

PurviewGA: Generally available

Insider Risk Management: risky AI usage

  • Microsoft 365 Copilot
  • Copilot Studio agents
  • Third-party AI apps

The risky AI usage policy template detects risky prompts and responses, including prompt injection attempts and access to protected materials, and feeds user risk scoring and adaptive protection.

Decision trigger
Use when AI rollout is broad and you need to spot the small number of users misusing it without monitoring everyone manually.
Licence signal
Microsoft 365 E5 or E5 Compliance. Insider Risk for agents needs Microsoft 365 E7 or Agent 365.
Evidence produced
  • Policy configuration and privacy settings
  • Alert triage and case outcomes
  • Adaptive protection levels applied
Framework mapping

ISO/IEC 42001

  • A.9.2 Processes for responsible use
  • A.6.2.6 Operation and monitoring

EU AI Act

  • Art. 26(5) Deployer monitoring

NIST AI RMF

  • MEASURE 2.4 Production monitoring
  • MANAGE 4.1 Post-deployment monitoring
Watch out

Prompt and response capture needs a collection policy in DSPM. Without it, the template sees far less than you think. Involve HR and privacy before enabling.

Microsoft Learn (opens in a new tab)

PurviewGA: Generally available

Communication Compliance for AI interactions

  • Microsoft 365 Copilot
  • Copilot Studio agents
  • Third-party AI apps

Detects regulatory and conduct violations in user prompts and AI responses using classifiers, with review workflows for compliance teams.

Decision trigger
Use in regulated sectors where AI-assisted communication is subject to conduct rules, or where your acceptable use policy bans specific content.
Licence signal
Microsoft 365 E5 or E5 Compliance.
Evidence produced
  • Policies covering AI interactions
  • Reviewer decisions and escalations
  • Trend reports for policy matches
Framework mapping

ISO/IEC 42001

  • A.9.2 Processes for responsible use
  • A.3.3 Reporting of concerns

EU AI Act

  • Art. 26(5) Deployer monitoring

NIST AI RMF

  • MANAGE 4.1 Post-deployment monitoring
Watch out

Scope tightly and document the lawful basis. Broad monitoring of staff prompts raises privacy and employment-relations risk in NZ, AU and the UK.

Microsoft Learn (opens in a new tab)

Stage 06

6. Assure and evidence

Can you prove to an auditor or regulator what happened and what you control?

Retained interactions, searchable records and a scored assessment turn controls into evidence. This is where governance stops being a slide and becomes defensible.

PurviewGA: Generally available

Audit, retention and eDiscovery for AI interactions

  • Microsoft 365 Copilot
  • Copilot Studio agents
  • Foundry and custom AI apps

Copilot and agent interactions flow into the unified audit log, can be retained or deleted under Data Lifecycle Management policies, and can be searched and held through eDiscovery.

Decision trigger
Set retention before go-live. Regulators and litigants will ask what the AI said, to whom and on what basis.
Licence signal
Audit (Standard) is broadly available. Longer audit retention and eDiscovery Premium need Microsoft 365 E5 or E5 Compliance.
Evidence produced
  • Retention policy for AI interactions
  • Audit search exports
  • eDiscovery holds and case records
Framework mapping

ISO/IEC 42001

  • A.6.2.8 Recording of event logs
  • Cl. 7.5 Documented information

EU AI Act

  • Art. 12 Record-keeping
  • Art. 26(6) Deployer log retention

NIST AI RMF

  • GOVERN 1.5 Ongoing monitoring and review
  • MANAGE 4.1 Post-deployment monitoring
Watch out

Retention cuts both ways. Keeping every prompt forever creates privacy exposure. Align AI retention with your records schedule and privacy principles.

Microsoft Learn (opens in a new tab)

PurviewGA: Generally available

Compliance Manager AI regulation assessments

  • Microsoft 365 Copilot
  • Copilot Studio agents
  • Foundry and custom AI apps
  • Third-party AI apps

Premium regulatory templates for AI, including the EU AI Act, NIST AI RMF, ISO/IEC 42001 and ISO/IEC 23894, with improvement actions that can share evidence across assessments.

Decision trigger
Use to track technical control status against a framework and to show progress to a risk committee.
Licence signal
AI templates are premium templates; availability depends on your Compliance Manager licensing.
Evidence produced
  • Scored assessment per framework
  • Improvement actions with owners and evidence
  • Assessment history over time
Framework mapping

ISO/IEC 42001

  • Cl. 9.1 Monitoring and measurement
  • Cl. 9.2 Internal audit (input)

EU AI Act

  • Art. 9 Risk management
  • Art. 17 Quality management (providers)

NIST AI RMF

  • GOVERN 1.1 Legal and regulatory requirements
Watch out

A Compliance Manager score is not certification and not a conformity assessment. It covers technical controls well and the management system poorly.

Microsoft Learn (opens in a new tab)

Licensing

What gates each capability

Through 2026 Microsoft moved agent-specific controls in Entra, Defender and Purview behind Agent 365 or Microsoft 365 E7. An E5 tenant secures people and Copilot well, but not agents. Budget for that before you scale agents.

Microsoft AI security capabilities and the licence that gates each one
DLP for Copilot prompts and label-based exclusionTenants with Microsoft 365 Copilot, free and paid, across E1, E3 and E5 per Microsoft's rollout notice
SharePoint Advanced Management oversharing controlsIncluded with at least one Microsoft 365 Copilot licence (restricted site creation by apps excepted)
Classic DSPM for AI, Insider Risk, Communication Compliance, eDiscovery PremiumMicrosoft 365 E5 or E5 Compliance
DSPM AI observability and Insider Risk for agents Microsoft 365 E7 or Agent 365
Conditional Access and ID Protection for agents Agent 365 or Microsoft 365 E7
Defender agent discovery and posture (Foundry and third-party cloud agents) Defender CSPM plus Agent 365, from 1 July 2026
Foundry guardrails, Prompt Shields, evaluationsAzure consumption
Compliance Manager AI regulation templatesPremium templates, per Compliance Manager licensing

Published USD list prices, mid-2026: Microsoft 365 E5 USD 60, Microsoft 365 Copilot USD 30, Entra Suite USD 12 and Agent 365 USD 15 per user per month. Microsoft 365 E7 bundles all four at USD 99. Regional and agreement pricing differs.

Reference architectures

Two governed patterns, layer by layer

Each layer names the controls that make it real. Select a control to jump to its card.

Governed Microsoft 365 Copilot rollout

An organisation licensing Copilot for knowledge workers that must show its board and regulator the rollout is controlled.

  1. 1

    Readiness

    Fix exposure first: oversharing baseline, restrict business-critical sites, label the crown jewels.

  2. 2

    Guardrails

    Prompt DLP in simulation, then enforce the highest-impact sensitive information types.

  3. 3

    Visibility

    Baseline Copilot and shadow AI usage so you can show the control effect over time.

  4. 4

    Detection

    Target the misuse minority, with HR and privacy agreement on scope.

  5. 5

    Assurance

    Retention aligned to your records schedule and a scored ISO/IEC 42001 assessment.

Governed agent: Copilot Studio or Foundry

A business unit building an agent that reads internal data and takes actions on behalf of users.

  1. 1

    Identity

    Every agent gets an Agent ID, a named sponsor and an entry in the registry.

  2. 2

    Access

    Least-privilege connectors, environment promotion path and a risk-based block.

  3. 3

    Build

    Prompt Shields for indirect injection and Purview coverage for custom app data.

  4. 4

    Test

    Evaluation and red-team thresholds act as the release gate.

  5. 5
  6. 6

    Evidence

    Interaction records and assessment history ready for audit.

30 / 60 / 90

A 90-day rollout that ends in evidence

  1. Days 0 to 30

    Phase 1: See and baseline

    1. 1.Turn on audit and DSPM, with the collection policy for Copilot interactions
    2. 2.Run the SharePoint oversharing baseline and rank sites by exposure
    3. 3.Enable the default Copilot DLP policy in simulation mode
    4. 4.Export the agent inventory and reconcile it against the Entra Agent Registry
    5. 5.Publish an AI acceptable use policy and stand up an AI register
    6. 6.Create an ISO/IEC 42001 assessment in Compliance Manager as the tracking frame

    Exit criteria

    One reconciled inventory of AI apps and agents, and a measured exposure baseline.

  2. Days 31 to 60

    Phase 2: Enforce

    1. 1.Move DLP to block for the two or three highest-impact sensitive information types
    2. 2.Apply label-based Copilot exclusion to the highest sensitivity labels
    3. 3.Apply Restricted Access Control to high-risk sites while permissions are cleaned up
    4. 4.Introduce Managed Environments, connector DLP and an agent promotion path
    5. 5.Migrate high-privilege agents to Agent ID and apply Conditional Access for agents
    6. 6.Enable risky AI usage and Communication Compliance policies with HR and privacy sign-off

    Exit criteria

    Top risks blocked, every production agent has an owner and an identity.

  3. Days 61 to 90

    Phase 3: Assure

    1. 1.Set retention for AI interactions in line with the records schedule
    2. 2.Make Foundry evaluation and red-team thresholds a release gate
    3. 3.Enable Defender AI posture and threat protection, with an AI incident playbook in the SOC
    4. 4.Complete impact assessments for higher-risk AI use cases
    5. 5.Report the first scored assessment and residual risks to the risk committee

    Exit criteria

    Evidence pack an auditor can test, and a quarterly review cadence agreed.

Field notes

Common pitfalls

  • Treating Copilot as the risk

    Copilot surfaces what users can already reach. The real risk is permissions sprawl and unlabelled data that AI makes visible. Fix access, not the assistant.

  • Blocking on day one

    DLP in block mode without simulation creates false positives and pushes users to unsanctioned tools. Measure first, then enforce narrowly.

  • Assuming E5 covers agents

    Agent Conditional Access, ID Protection, agent observability and Defender agent posture now sit behind Agent 365 or E7. Scope licences per control, not per suite.

  • One policy for every agent identity

    Agent identities and agent user accounts are separate Conditional Access targets. A policy scoped to one leaves the other open.

  • Hiding content instead of fixing access

    Restricted Content Discovery is a stopgap. Overuse degrades search and Copilot quality and leaves the underlying permissions untouched.

  • Mistaking a dashboard for assurance

    A Compliance Manager score is useful tracking, not certification. Auditors also test policy, impact assessments, risk decisions and management review.

The management system

What Microsoft tooling does not do for you

The Microsoft stack is strong on technical controls and telemetry. ISO/IEC 42001, the EU AI Act and national guidance also expect a management system that no product switches on.

Management system elements that Microsoft tooling does not provide
AI policy, objectives and risk appetiteISO/IEC 42001 Cl. 5 to 6, A.2
AI system impact assessmentsISO/IEC 42001 A.5, EU AI Act Art. 27 (FRIA, where applicable)
Risk treatment and acceptance decisionsISO/IEC 42001 Cl. 6.1, NIST AI RMF MANAGE 1
Supplier and third-party AI due diligenceISO/IEC 42001 A.10, NIST AI RMF GOVERN 6
Human oversight design for each use caseEU AI Act Art. 14, Art. 26(2)
Competence and AI literacyISO/IEC 42001 Cl. 7.2, A.4.6
Internal audit and management reviewISO/IEC 42001 Cl. 9.2 to 9.3

The efficient pattern is one control model: implement a control once, map it to every framework you answer to, and let Microsoft telemetry feed the evidence automatically.

Regional overlays

Where the controls land in NZ, Australia, the UK and the EU

New Zealand

Principles-based, non-binding guidance for the public service; Privacy Act 2020 applies to everyone

  • The Public Service AI Framework sets principles for AI across the public service and sits within the National AI Strategy launched in July 2025.
  • The GCDO's Responsible AI Guidance for the Public Service: GenAI covers governance, AI use registers and procurement.
  • Cabinet agreed in June 2024 to follow the OECD AI Principles.
  • Privacy Act 2020: IPP 5 (security safeguards) and IPP 11 (disclosure) are where Copilot data controls land; NZISM applies for agencies.

Australia

Voluntary national guidance aligned with ISO/IEC 42001 and NIST AI RMF

  • The National AI Centre's Guidance for AI Adoption (October 2025) condenses the 2024 Voluntary AI Safety Standard's 10 guardrails into six essential practices.
  • The six practices: decide who is accountable, understand impacts and plan accordingly, measure and manage risks, share essential information, test and monitor, maintain human control.
  • Implementation Practices align with ISO/IEC 42001 and NIST AI RMF, and include an AI register template.
  • Privacy Act 1988 APP 11 (security of personal information) applies to AI processing.

United Kingdom

Voluntary codes plus UK GDPR

  • DSIT's AI Cyber Security Code of Practice (January 2025) sets 13 lifecycle principles and is the basis for the ETSI standard TS 104 223.
  • Principles include evaluating threats, enabling human responsibility, tracking assets and securing the supply chain, which map directly to the Discover, Identity and Build stages.
  • UK GDPR and ICO guidance on AI and data protection govern personal data in prompts, grounding and retention.

European Union

Binding regulation, amended by the AI Omnibus in 2026

  • The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026.
  • Stand-alone high-risk systems (Annex III) now apply from 2 December 2027; high-risk AI in regulated products (Annex I) from 2 August 2028.
  • Prohibited practices have applied since February 2025 and general-purpose AI model obligations since August 2025, unaffected by the deferral.
  • Most Copilot productivity use is not high-risk. The articles cited on this page are used as the strongest benchmark for deployer evidence, not a claim that every use case is in scope.
FAQ

Questions we get asked

Does Microsoft 365 E5 cover AI agent security?

Partly. E5 covers Purview data security, Insider Risk and Communication Compliance for Copilot. Conditional Access and ID Protection for agents, AI observability for agents and Defender agent posture for Foundry and third-party agents require Agent 365 or Microsoft 365 E7 as of 2026.

What is Microsoft Agent 365?

Agent 365 is Microsoft's control plane for deploying, organising and governing AI agents. It became generally available on 1 May 2026 at USD 15 per user per month, and is included in Microsoft 365 E7.

Can Purview stop sensitive data being typed into Copilot?

Yes. DLP for Microsoft 365 Copilot can block Copilot from responding to prompts that contain selected sensitive information types, and can exclude labelled files and emails from Copilot grounding.

Does Compliance Manager make us ISO/IEC 42001 compliant?

No. Compliance Manager has an ISO/IEC 42001 template that tracks technical controls, but certification also requires an AI management system: policy, impact assessments, risk treatment, internal audit and management review.

When do EU AI Act high-risk obligations apply?

Following the AI Omnibus, Regulation (EU) 2026/1744, Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. Prohibited practices and general-purpose AI obligations already apply.

Rolling out Copilot or agents in NZ, Australia or the UK?

CybrGen runs Copilot and agent governance readiness assessments that combine this control set with an ISO/IEC 42001-aligned management system, so you finish with working controls and an evidence pack, not a slide deck.

Talk to Krish