Microsoft Scout: What Microsoft's Always-On Agent Is, Who Can Try It, and What to Prepare Before It Reaches Your Tenant
On June 2, 2026, Microsoft introduced Scout on the Microsoft 365 Blog and called it "our first Autopilot agent": an always-on agent that works autonomously, has its own identity, and acts on your behalf. It is not for sale. At the time of writing it is an experimental release for organizations enrolled in Frontier, plus a private preview, with no price and no general-availability date published. This article covers what an agent with its own Entra identity means for a 20–500-seat tenant, and the governance work that pays off whether or not you enroll.
What Microsoft Scout is, in Microsoft's words
Microsoft describes Scout as the first of a category it calls Autopilot agents: "always-on agents that work autonomously, with their own identity, and act on your behalf." Where Microsoft 365 Copilot waits for a prompt, Scout runs continuously and takes the initiative.
The announcement lists what it does: it proactively schedules and coordinates meetings across time zones, flags the meetings that matter, generates preparation materials, identifies upcoming deliverables and blocks calendar time for them, and spots risks such as stalled decisions. It "builds context powered by Work IQ", Microsoft's name for the layer that reads a user's work signals.
Its reach is the part an IT manager should read twice. Scout connects across Teams, Outlook, OneDrive and SharePoint, to chats, email, calendar and contacts. It operates across cloud, desktop and web, and through the desktop app it extends to the browser, local resources and Model Context Protocol (MCP) servers.
Scout is "powered by OpenClaw open-source technology", with Microsoft contributing policy conformance work upstream.
What an agent with its own identity means for a 20–500-seat tenant
The governance model in the announcement is specific, and it is the reason Scout is worth studying even if you never install it.
- Identity. Scout runs "under its own governed Entra identity, not a shared, anonymous service account." That is a new kind of directory object: an agent identity that belongs to a person and acts for them.
- Credentials. They are "scoped to the task at hand, redacted from logs or diagnostics."
- Reach. Agents "can only reach the resources and destinations you've approved."
- Approval. "Sensitive actions can require a human to sign off before they proceed."
- Data protection. Purview sensitivity labels and data loss prevention "are enforced in the moment."
Each line maps to a control you either have or do not have. Unowned service accounts with standing permissions become a bigger problem when every user gains an agent identity. If sensitivity labels exist only in a plan, "enforced in the moment" enforces nothing. Our post on agent governance covers the ownership, blast-radius classification and monitoring model this kind of agent assumes is already in place.
Who can try it now, and the prerequisites Microsoft lists
From the announcement: after internal use by Microsoft employees, Scout is extending "to a select group of customers in private preview and to Frontier organizations" as "an experimental release through Frontier." Frontier is Microsoft's opt-in program for experimental Microsoft 365 releases.
The gates Microsoft names: "Access requires Frontier enrollment, Intune policy configuration, and an opt-in attestation." After that, "Users with a GitHub Copilot license can then download and install the experience." Setup instructions are published at learn.microsoft.com/microsoft-scout.
Third-party reports of Microsoft's setup documentation add the following at the time of writing (we did not open Microsoft Learn; verify current requirements there before you plan around them):
- Two admin gates: Frontier enabled for the organization in the Microsoft 365 admin center, and the Scout app enabled on devices through an Intune policy plus an administrator attestation.
- A GitHub Copilot Business or Enterprise license for each user, because Scout uses the user's GitHub account for token billing.
- The attestation exists because Scout can route data outside Microsoft 365 to third-party inference paths; an administrator has to acknowledge that and opt in.
Microsoft has published no price for Scout and no general-availability date at the time of writing, and we are not going to guess at either. Note what the announcement does not say: it does not state that a Microsoft 365 Copilot license is required. The license it names is GitHub Copilot.
The governance homework that pays off whether or not you enroll
Everything Scout enforces "in the moment" depends on decisions made before the moment. This is the same list we work through for Copilot Studio agents and Microsoft 365 Copilot, so none of it is wasted if you wait.
- Sensitivity labels and DLP in production. A tenant with no published labels and a default DLP configuration gives Scout nothing to enforce. Put Microsoft Purview controls in place before Copilot explains the order: labels, DLP, retention, audit.
- An inventory of non-human identities. List every service principal, managed identity, Copilot Studio agent and SharePoint agent with an owner, a purpose and a review date. Our AI Agent Inventory and Lifecycle Governance Implementation builds that registry in the admin center rather than in a spreadsheet.
- Conditional Access for workload identities. User policies do not apply to an identity that is not a user. Conditional Access for workload identities is a separately licensed Entra capability (Microsoft Entra Workload ID); confirm the current requirement on Microsoft Learn.
- Least privilege on what agents reach. "Only the resources and destinations you've approved" is only as safe as the approval. AI Security: Reduce Microsoft 365 Copilot and Agent Risk walks through oversharing, app consent and connectors.
- Audit you can read. Confirm which agent actions land in the unified audit log and how long you keep it.
- A human sign-off rule. Decide in advance what counts as sensitive (external email, executive calendars, finance or HR data) so the approval step is a policy rather than a per-user preference.
If you want the list executed rather than read, AI Security for Microsoft 365 Copilot and Agents does the inventory, risk register and pilot controls in two to three weeks.
How Scout relates to Microsoft 365 Copilot, Copilot Studio agents and Agent 365
The names overlap enough to confuse a budget meeting, so here is the split at the time of writing:
- Microsoft 365 Copilot is the per-user assistant inside Word, Excel, PowerPoint, Outlook and Teams. You prompt it; it answers under your identity. It is a purchasable add-on at Microsoft's list price on our Microsoft 365 Copilot page.
- Copilot Studio agents are agents you build: a defined audience, approved knowledge sources, a small set of actions, published to a channel, running under the connections you configure.
- Agent 365 is the control plane: inventory, ownership, lifecycle, monitoring and compliance evidence for the agents in your tenant. Copilot Studio vs Agent 365 explains when each enters the plan.
- Scout is a Microsoft-built agent you do not author. It runs always-on, under its own governed Entra identity, on a person's behalf, gated by Frontier enrollment, an Intune policy and an attestation rather than by a publish step.
The practical consequence: Scout belongs in the same inventory and review cycle as the agents you build yourself. The difference is that you cannot change its design, only govern its reach. For the agents you do build, the Copilot Studio Agent Security Review and Red-Team Test ($2,950) covers the design side.
Frequently asked questions
Does Microsoft Scout require a Microsoft 365 Copilot license?
The announcement does not say so. The license it names is GitHub Copilot: after Frontier enrollment, Intune policy and attestation, "users with a GitHub Copilot license can then download and install the experience." Check the current prerequisites on Microsoft Learn before buying anything for Scout.
What does Scout cost?
Microsoft has published no price at the time of writing. Third-party reports of the setup documentation say the user's GitHub Copilot account is used for token billing, which is why a GitHub Copilot Business or Enterprise license is listed; verify on Microsoft Learn.
When will Scout be generally available?
No general-availability date has been published. At the time of writing it is an experimental release through Frontier plus a private preview for a select group of customers.
Can Scout read files outside Microsoft 365?
Through the desktop app it extends to the browser, local resources and MCP servers, within the resources and destinations an administrator has approved. Because it can route data outside Microsoft 365 to third-party inference paths, an administrator must attest and opt in before it is enabled.
Can we keep Scout out of our tenant until we are ready?
Yes. Nothing runs without Frontier enrollment, an Intune policy and an administrator attestation; a tenant that has not opted in does not get Scout.
Sources
- Microsoft 365 Blog, June 2, 2026: "Introducing Microsoft Scout: Your always-on personal agent" (opened; all quotations above)
- Microsoft Learn: Microsoft Scout setup and admin documentation (referenced, not opened; requirements as reported by third parties at the time of writing)
- IT Partner blog: content/blog/new/what-is-agent-governance-and-why-your-business-needs-it-in-2026.json; copilot-studio-vs-agent-365-building-your-first-ai-agent.json; ai-security-protecting-your-business-from-copilot-and-agent-risks.json; why-you-must-deploy-microsoft-purview-before-copilot.json
- IT Partner pages: content/services/PRP-AISEC-001, ITPWW460SECOT, PRP-CPLT-001 and ITPWW1010IMPOT; content/subscriptions/CFQ7TTC0MM8R__Commercial.json
- IT Partner engineering notes, September 2026
| Question | Enroll now if | Wait if |
|---|---|---|
| Do we already run experimental releases through Frontier? | Yes, with a named owner | Enrollment would be new and nobody owns it |
| Are Purview labels and DLP published and in use? | Labels are applied and DLP policies are enforced | Labels exist only as a plan |
| Do the intended users hold GitHub Copilot Business or Enterprise licenses? | Yes, and the GitHub account model is understood | Licenses would be bought only for Scout |
| Can we accept data routing outside Microsoft 365 to third-party inference paths? | Legal and security have answered the attestation question | Regulated data has no exception process |
| Is there an inventory of non-human identities with owners? | Yes, and agent identities can be added to it | Service accounts are unowned today |
| Can we scope it to a pilot group through Intune? | A pilot device group exists with compliance policies | Devices are unmanaged or partly enrolled |
Key takeaways
- Scout is Microsoft's first Autopilot agent: always-on, autonomous, with its own governed Entra identity, announced June 2, 2026 and available only as an experimental Frontier release and a private preview.
- Access requires Frontier enrollment, an Intune policy and an administrator attestation; users then need a GitHub Copilot license. No price and no general-availability date have been published.
- The desktop edition reaches the browser, local resources and MCP servers, so device management and the attestation about third-party inference paths are part of the decision.
- The governance Scout enforces (labels, DLP, approved resources, human sign-off) only works if those decisions already exist in your tenant.
- Treat Scout as one more agent in the same inventory as Copilot Studio agents and Agent 365, with an owner, a scope and a review date.
If you are deciding whether to enroll, the Microsoft 365 Copilot Readiness Assessment ($4,950, one to two weeks) checks the labels, DLP coverage, permissions and licensing prerequisites that Scout and Microsoft 365 Copilot both depend on. For tenants that already run agents, AI Security for Microsoft 365 Copilot and Agents inventories them and stands up the controls. Scout itself has no published price at the time of writing.
Questions this article didn’t answer?
Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.