AI Agent Inventory and Lifecycle Governance Implementation
AI Agent Inventory and Lifecycle Governance Implementation stands up agent governance in your Microsoft 365 tenant as a working system, not a policy document. In three weeks IT Partner discovers every agent you actually have — Copilot Studio, SharePoint agents, Microsoft 365 Copilot agent builder, Microsoft Foundry-hosted, and third-party or directly registered agents — and populates the agent registry in the Microsoft 365 admin center (and the Agent 365 surfaces where you hold that license) with a named owner and business sponsor, purpose, approved knowledge sources and connectors, publish scope and a review date for each. We configure the intake-and-approval workflow that decides who may publish, to whom and with which data; apply Microsoft Entra Agent ID controls — Conditional Access on agent identities, access packages with sponsor-driven renewal where your licensing supports them, least-privilege permissions; set the Power Platform data policies and environment rules that enforce the allow-lists mechanically; document the review cadence and the retirement procedure; and run the first review with your team. $4,950 per project, fixed, for a registry and workflow covering up to 25 agents (larger estates quoted), and you pay after you approve delivery. Agent 365, Microsoft Entra and Microsoft 365 Copilot licenses are Microsoft's charges and are not included.
What this engagement is
Agents multiply faster than any earlier class of Microsoft 365 object because four different tools let people create them: Copilot Studio in a Power Platform environment, the agent builder inside Microsoft 365 Copilot, a SharePoint site owner's "create an agent" button, and a developer's Microsoft Foundry project — plus whatever a vendor registers into the tenant. In 2026 Microsoft turned governing them into a product category. Microsoft Agent 365 reached general availability on 1 May 2026 as the control plane for agents; Copilot Studio has created a Microsoft Entra Agent ID automatically for every new agent since 18 March 2026, and the environment-level opt-out has since been removed; the agent registry moved out of the Microsoft Entra admin center into the Microsoft 365 admin center under Agents > All agents, and the legacy Entra agentRegistry Graph API was retired in August 2026. That admin-center page now opens with three tiles — total agents, agents without owners, unmanaged agents — and in most tenants we open, the first number is a surprise and the second is not zero. That is the moment this engagement is built for: the platform can finally see the agents; nobody has yet decided who owns each one, what it may read, who it may be published to, or when it gets retired. The engagement builds the operating system around that registry, in a deliberate order. Discovery first, from every source, because the registry only lists what the platforms report: the admin-center export with its thirty-plus attributes per agent, the Copilot Studio and Power Platform admin center inventories, the Microsoft Entra enterprise applications and agent identities that Copilot Studio tags on creation, Foundry projects and their agent identities, SharePoint agents by site, and any third-party agents registered directly. Every agent then gets a record — a named owner and a business sponsor (the two roles Microsoft Entra Agent ID separates on purpose: the person who can fix the agent and the person accountable for whether it should exist), purpose, approved knowledge sources and connectors, publish scope, review date — written into the registry and the agent's Entra identity where the platform holds a field for it, and into the governance workbook where it does not. The intake-and-approval workflow comes next: which agent types users may install, who may share, which users or groups may use agents at all, and the admin-center Requests queue where an agent published by a maker waits for a reviewer to check its data sources, tools and permissions before it is published to a scoped audience or rejected — configured, documented and tested end to end with a real submission. Identity controls follow for the agents that carry a Microsoft Entra Agent ID: Conditional Access policies scoped to agent identities and their blueprints, custom security attributes so a policy applies to a class of agents rather than a hand-kept list, and — where Microsoft's licensing for governing agent identities is in place — access packages with an expiry date, so a sponsor is asked to renew the agent's access instead of the access living forever. Power Platform data policies and environment rules then enforce the connector and knowledge-source allow-lists mechanically, so the approval workflow is not the only thing standing between a maker and a public-website knowledge source. The review cadence and the retirement procedure are written last, and the first review is run with your team before we leave. A licensing boundary, stated plainly because Microsoft's line moves. The Microsoft 365 admin center registry, the ownerless-agent view, block and delete, the export, the Requests queue, the allowed-types, sharing and user-access settings and the read-only data-and-tools view of each agent are available to Microsoft 365 Copilot-licensed tenants without an Agent 365 license, and Microsoft Entra Agent ID itself is available to every Microsoft Entra tenant. Extending Entra's security features to agents is where Agent 365 is required: Conditional Access for agents needs Microsoft Entra ID P1 or P2 plus an Agent 365 license per user (Microsoft says enforcement of that licensing check is coming), and governing agent identities with access packages needs Microsoft 365 E7, or an Agent 365 license paired with at least Entra ID P1 or Microsoft 365 E3 — Microsoft's documentation as of June 2026. Agent 365 lists at $15 per user per month standalone at the time of writing, on top of a qualifying base plan, and is included in Microsoft 365 E7. We read your entitlements at intake, configure what they allow, and record in the governance workbook exactly which controls are waiting on a license. We do not buy anything on your behalf; the decision is yours, at Microsoft's list price if you buy through us. Boundaries, drawn honestly. This is the one-time build that our adjacent services assume exists: AI Security for Microsoft 365 Copilot and Agents is the tenant-wide security baseline that inventories agents as a finding and configures guardrails where approved; Managed AI Agent Operations and Optimization is the monthly operation of agents already in production; the AI Governance and ISO/IEC 42001 Readiness Assessment is the management-system view for organizations heading to certification. Building agents is Custom Agent Development with Microsoft Copilot Studio or AI Agent Development with Microsoft Foundry; the wider Power Platform operating model is Power Platform Governance and Center of Excellence Setup; governance of human identities — PIM, access reviews, lifecycle workflows — is Microsoft Entra ID Governance Implementation. Security testing of an individual agent's prompts and actions is a separate, per-agent review, not this engagement. If you want the thinking behind the controls before you buy them, our agent governance primer is the place to start.
Success criteria
What you receive
How the work unfolds
Read-only collection from every source: the Microsoft 365 admin center registry export, the Copilot Studio and Power Platform admin center inventories, Microsoft Entra enterprise applications and agent identities (Copilot Studio tags the service principals it creates, which is how the pre-March-2026 agents are found), Foundry projects, SharePoint agents by site, and any directly registered agents. Licensing entitlements read from the tenant. No agent is touched.
One working session with the Copilot or AI program owner, IT, security and the two or three most active makers: ownership and sponsorship model, classification tiers, knowledge-source and connector allow-lists, publish-scope rules, allowed types, sharing and user access, Conditional Access and access-package design, review cadence, retirement criteria. Every control we configure traces to a decision made here.
Owner, sponsor, purpose, approved sources, publish scope and review date recorded per agent; owners and sponsors attest; ownerless agents reassigned or queued for retirement; legacy-identity Copilot Studio agents classified with a decision each.
Allowed agent types, sharing and user-access settings applied; the Requests queue reviewer role and checklist go live and are tested with a real submission; Conditional Access policies on agent identities and blueprints created in report-only first, then enforced with your approval; custom security attributes assigned; access packages built where licensed; least-privilege permission clean-up.
Data policies and Copilot Studio governance rules built to mirror the allow-lists, the impact analysis run against every in-scope agent, enforcement staged from non-production to production, the exceptions process live.
The retirement procedure executed on a real unused or orphaned agent; the review cadence run once with your admins and sponsors; the runbook, licensing gap register and decisions workbook handed over and walked through; temporary access removed.
Prerequisites
Who does what
IT Partner
- Produce the inventory and licensing evidence and put every governance decision in front of you with trade-offs before configuring anything.
- Populate the registry, run the ownership and sponsorship attestation, and classify legacy-identity agents against Microsoft's guidance.
- Configure the intake-and-approval workflow, Conditional Access, custom security attributes and access packages where licensed, and the least-privilege permission clean-up.
- Build the Power Platform data policies and governance rules, run the impact analysis, stage enforcement and stand up the exceptions process.
- Write the review cadence and retirement runbook, execute the retirement drill and the first review with your team, and deliver the licensing gap register.
- Remove any temporary access we were granted at handover.
Your team
- Make the governance decisions in the workshop — we implement your policy, not a template imposed on you.
- Provide the delegated access requested, licensing visibility, test accounts and a test agent for the workflow validation.
- Name an owner and a sponsor for every agent, or approve its retirement; arbitrate the agents nobody will claim.
- Send the attestation, workflow and enforcement communications through your channel on the agreed schedule.
- Approve Conditional Access enforcement, the retirement queue and each licensing decision explicitly.
- Own the review cadence after handover — or engage the monthly operations service to run it.
What's not included
Limitations & technical notes
Frequently asked questions
We were already looking at the AI Security engagement. Why is this a separate service?
Because they answer different questions. AI Security for Microsoft 365 Copilot and Agents is the security baseline: it inventories your Copilot and agent estate as a finding, configures Purview, Defender and Entra controls, and configures agent guardrails where you approve them. This engagement is the operating system those guardrails sit inside — a registry where every agent has an owner and a sponsor, an approval path a maker actually follows, identity controls tied to agent identities, and a review cadence and retirement procedure that are run rather than written. Either can go first; if the security review has already told you that 40 agents have no owner, this is the engagement that fixes it.
Do we need an Agent 365 license for this?
Not for most of it. The Microsoft 365 admin center's registry, ownerless-agent view, export, block and delete, the Requests approval queue, allowed-types, sharing and user-access settings, and the read-only data-and-tools view are available to Microsoft 365 Copilot-licensed tenants without Agent 365, and Microsoft Entra Agent ID itself is available to every Entra tenant. Agent 365 is required to extend Entra's security features to agents: Conditional Access for agent identities (with Entra ID P1 or P2) and access packages for agent identities (Microsoft 365 E7, or Agent 365 with at least Entra ID P1 or Microsoft 365 E3), plus Agent 365's own observability and risk views. We read your entitlements at intake, configure what they allow and hand you a gap register naming which control waits on which license — at $15 per user per month standalone at the time of writing, or inside Microsoft 365 E7, bought at Microsoft's list price whether through us or not.
How do you find agents we do not know about?
By not trusting any single list. The admin-center registry export gives thirty-plus attributes per agent it knows about; the Copilot Studio and Power Platform admin centers list agents by environment, including ones never published to Microsoft 365; Microsoft Entra shows the enterprise applications Copilot Studio created for older agents, which carry a tag naming their origin, and the agent identities newer agents and Foundry projects receive; SharePoint agents are found site by site; and the registry's own "unmanaged agents" tile flags agents created or managed outside Agent 365. We reconcile those sources into one inventory and then ask the makers what is missing — the last step usually finds the agent running on someone's personal connection.
What is the difference between an agent's owner and its sponsor, and why do you insist on both?
Microsoft Entra Agent ID separates them deliberately. The owner is the technical administrator — the person who can change the agent's configuration and credentials, re-enable it, restore it. The sponsor is the business representative accountable for whether the agent should exist and what it may access: they approve or decline renewal, request access on the agent's behalf, and can disable or soft-delete it, but cannot change its settings. Microsoft requires a sponsor on every agent identity and blueprint, and if a sponsor leaves, sponsorship transfers to their manager so someone accountable always remains. We record both for every agent, including those whose platform holds no field for it, because an agent with only a technical owner is an agent nobody will ever decide to switch off.
Our Copilot Studio agents were built last year. Do they have Microsoft Entra Agent IDs?
Probably not. Copilot Studio began creating an agent identity automatically for every new agent on 18 March 2026; agents created before that, or in an environment that had opted out, authenticate with platform-managed service principals that Entra treats as ordinary applications — so agent-specific Conditional Access and governance do not apply to them. There is no in-place conversion and republishing does not create one. Microsoft's guidance is to classify those agents by usage: decommission the unused ones, recreate medium-usage ones with an agent identity, and leave production-critical ones alone until an automated migration path ships — Microsoft has said existing app-registration agents will be migrated in a future update. We do the classification and the decision record here; recreating an agent is development work, scoped separately.
What does the approval workflow look like for a maker?
A maker builds in Copilot Studio, Foundry or the agent builder and publishes to the organization; the agent lands in the Requests queue in the Microsoft 365 admin center as pending review, with its description, owner, data sources, tools and permissions attached. The reviewer we define — with a checklist and a turnaround you chose — checks those against the allow-list for the agent's tier, then either publishes it to a scoped audience with a policy template applied and permissions consented, or rejects it with a reason. Updates to a published agent queue the same way and the old version stays live until approved. Around that queue sit the settings that decide who may share agents and who may use them at all, and the maker page that says what gets approved quickly. We test the whole path with a real submission before calling it live.
Will Conditional Access break our agents?
Not if it is introduced the way we do it. Policies targeting agent identities and blueprints are created in report-only mode first, so the sign-in log shows what would have been blocked before anything is; enforcement follows your approval. The patterns matter: an agent acting on a user's behalf is evaluated as that user, so the user's existing policies already apply; an autonomous agent using its own identity is where an agent policy bites; an agent reaching your data with an API key is invisible to Conditional Access altogether. We document which of your agents fall into which pattern, and we say plainly that Conditional Access does not apply while security defaults are enabled — a tenant still on security defaults has an earlier conversation to have.
What happens when an agent's owner leaves the company?
Today, usually nothing — the agent keeps running on a disabled person's ownership until the admin center's "Agents without owners" tile catches it or a connection expires. After this engagement three things catch it: the registry record names a sponsor as well as an owner; the admin-center management rule that reassigns ownerless agent builder agents to the previous owner's manager is enabled where you chose it; and for agents with a Microsoft Entra Agent ID, sponsorship transfers to the departing sponsor's manager automatically, with lifecycle-workflow notifications where licensed. The monthly review then treats any ownerless agent as an action, not a statistic.
What is in the retirement procedure?
Order matters, which is why it is written down. Unpublish or delete the agent in its authoring tool first — Microsoft warns that deleting a Copilot Studio agent's app registration before unpublishing breaks its authentication; then remove its API permissions and connections, disable its Entra identity or block it in the admin center, soft-delete rather than hard-delete so there is a recovery window, and record the retirement with who approved it. The mechanics differ by platform — blocking a SharePoint or Foundry agent in the admin center affects only its availability in Copilot Chat, and only agent builder agents can be deleted from there — so the runbook is per platform. We run it once with you on a real agent so the first retirement is not the one that matters.
Does this cover SharePoint agents and agent builder agents, or only Copilot Studio?
All of them, with the honest per-platform differences stated. SharePoint agents are governed by site settings and by the registry once they surface there; agent builder agents are the only ones the admin-center sharing control governs and the only ones the ownerless-reassignment rule can act on; Copilot Studio agents are additionally governed by Power Platform data policies and environment rules and carry Entra agent identities when created after March 2026; Foundry agents receive agent identities automatically and are managed largely from Foundry. The inventory records the platform for every agent, and the runbook says which lever works on which.
Who runs the reviews after you leave?
Your admins and the sponsors, from the runbook — the monthly checks are ownerless agents, agents at risk, pending requests, expiring access and unused agents, and the quarterly pass re-reads allow-lists and tiers. That is why the first review is run with you inside the engagement rather than described in a document. If you would rather we run it, Managed AI Agent Operations and Optimization is a monthly service with no lock-in; you can stop it at any time. Organizations that buy their Microsoft licensing through IT Partner also have business-hours break-fix support included, so a question about the registry after handover is a ticket, not a quote.
We received Message Center notices about the Entra agent registry API being retired. Does that affect us?
Only if something in your tenant registered agents directly through the old Microsoft Entra agentRegistry Graph API. Microsoft retired the Entra admin center's registry blades on 1 May 2026 in favour of the Microsoft 365 admin center, and retired the legacy API in August 2026 after moving the date back from June; agents created in Copilot Studio or Foundry were never affected, and the replacement Agent 365 registration API requires an Agent 365 license in the tenant. Discovery includes checking whether any custom or vendor agent depended on the old API, and the inventory records what it was replaced with.
How long does it take, and what moves the price?
Three weeks: discovery and the decisions workshop in the first, registry population, the approval workflow and the identity controls in the second, Power Platform enforcement, the retirement drill, the first review and handover in the third. $4,950 per project, fixed, for one tenant and up to 25 agents, quoted in writing before work begins — you pay after you approve delivery. More agents, several tenants, a Government cloud or a sprawling multi-environment Power Platform estate change the quote, not the shape; recreating legacy-identity agents and testing individual agents are separate engagements and are named as such rather than absorbed.