AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·Buyers Guide9 read

Agent 365 vs Third-Party Agent Security: What Each Covers

A July 1 licensing change made this urgent: tenants without Agent 365-eligible licensing lost agent discovery in Defender. What Microsoft's agent stack genuinely does well, the four gaps, and why serious agent estates run both layers — like a CMDB and an EDR.

P
Priya Sundaram
Head of Vendor & Procurement Research
2026-08-06

Since July 1, 2026, a quiet licensing change has been making this question urgent: agent discovery, posture management, and threat detection for Copilot Studio and Microsoft Foundry agents in Defender now require Agent 365-eligible licensing — and tenants without it lose those capabilities. Organizations that assumed agent visibility came with their existing Microsoft security stack woke up in July to find it was now a product decision. So: what does Agent 365 actually cover, what does it genuinely do well, and where do third-party agent-security platforms still earn their line item?

The one-paragraph answer: Agent 365 is the right system of record for agents living inside the Microsoft ecosystem — registry, identity via Entra Agent ID, posture, and M365-native controls, now extending to cross-cloud registration. It is not a runtime enforcement layer for the agent behaviors that cause incidents, it is thin outside the Microsoft perimeter, and its visibility is now license-gated. Most enterprises with serious agent estates will run it and an independent runtime layer, for the same reason they run both a CMDB and an EDR.

Last verified: August 6, 2026. Disclosure: we build in the third-party category being compared.

What Agent 365 covers well

  • Registry and identity. A tenant-wide agent inventory built on Entra Agent ID (GA since April 2026) — agents as first-class identities rather than shared service accounts, now targetable by Conditional Access. This is foundational and Microsoft is genuinely ahead here.
  • Reach beyond Azure. The May 2026 update added cross-cloud registry support (agents on Bedrock and Google Cloud can register) and endpoint agent controls — a real step out of the walled garden.
  • Governed citizen development. The Agent Store's "built by your org" flow gives Copilot Studio agents an approval path, an owner of record, and a distribution channel that is not a Teams message with a link.
  • Defender and Purview integration. For licensed tenants: posture assessment, threat detection, prompt-injection protections (preview), and audit flowing into the tooling your SOC already runs.

Where the gaps are

1. The licensing wall is the first gap

Visibility that arrives with licensing departs with licensing. The July 1 change is worth reading precisely: unlicensed tenants lose agent discovery in Defender — the "am I safe by default?" assumption is now answered no. And the schema migration that came with it (AIAgentsInfo → AgentsInfo) silently broke existing hunting queries, which is its own small lesson about building your only visibility on a platform's product decisions.

2. Registration is not observation

A registry knows what agents are; incidents are caused by what agents do. The July–August incident record — an autonomous agent traversing Hugging Face's production systems, credential exfiltration through a coding agent at Roblox, injection persisting across framework memory at Black Hat — happened at runtime, in the tool-call layer. Independent runtime inspection of every action, argument, and retrieved context, with policy enforced inline, is a different discipline from posture scoring, and it is where our product lives.

3. Outside the ecosystem, coverage thins fast

LangChain, CrewAI, and custom Python agents on developer laptops; MCP servers in dotfiles; agentic browsing that just folded into ChatGPT itself; local models with tool access. Cross-cloud registration helps the agents someone chooses to register — the 1Password finding that 40% of organizations have agents reaching data beyond approved scope describes exactly the population that never gets registered.

4. The referee problem

Microsoft governing Microsoft agents has the same structural tension as any platform grading its own homework. For regulated deployments where deployer oversight duties need independent evidence — EU AI Act Article 26 being the obvious case — an audit trail that exists outside the platform being audited is not paranoia; it is the assignment.

The comparison, honestly

CapabilityAgent 365Independent runtime layer
Agent registry & identity (Microsoft estate)Strong — the reference implementationConsumes it, doesn't replace it
Posture for Copilot Studio / Foundry agentsStrong (with licensing)Partial
Runtime tool-call inspection & inline blockingLimitedCore function
Non-Microsoft frameworks & unregistered agentsThinCore function
MCP servers, endpoints, local agentsEarlyCore function (endpoint-level discovery)
Cross-platform policy (one rulebook for Copilot + ChatGPT + Claude + custom)NoCore function
Platform-independent audit evidenceBy definition, noYes

FAQ

We're all-in on Microsoft. Is Agent 365 enough?

If every agent you run is Copilot Studio or Foundry, registered, and licensed — it covers the inventory and posture layers well, and you should deploy it. The residual question is runtime: whether you need independent inspection of what those agents actually do. Your agent count and blast radius answer that, not vendor marketing — ours included.

Does AccuroAI replace Agent 365?

No, and we would not pitch it that way. Registry and identity belong to the platform; runtime governance and cross-platform policy benefit from independence. The architectures compose — Entra Agent ID identities are exactly what our attribution consumes on Microsoft estates.

What happened to our agent visibility on July 1?

If your tenant lacks Agent 365-eligible licensing, agent discovery/posture/detection features in Defender were withdrawn, and hunting queries against the old AIAgentsInfo schema broke. Check both before assuming your dashboards are telling the truth.

What should we actually do this quarter?

Inventory first — including the agents no registry knows about (per IBM's Think research, only 18% of organizations hold a complete agent inventory). Then decide the licensing question with the gap list in hand rather than before it.

Sources: What's New in Microsoft Security, July 2026 · Microsoft Entra Agent ID documentation · 1Password agent governance survey (July 2026) · Hugging Face incident disclosure (July 2026) · IBM Think 2026 agent inventory research. Licensing details per Microsoft communications as of August 2026 — verify current terms.

Related: Agent 365 + Claude Managed Agents: A CISO Field Guide · Guardian Agent Vendor Evaluation · AI Agent Security · NHI Is Dead, Long Live Agentic Identity.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security