Every layer of the agent stack meters the thing that grows — tokens, runs, tool calls, sandbox minutes — except the layer whose entire job is to stop the thing from growing. Microsoft Agent 365 went generally available on 1 May 2026 at $15 per user per month, licensed per human, with no per-agent fee at all: deploy fifty agents or five thousand and the invoice is identical. That is a genuinely good deal and it quietly removes the last automatic brake on fleet size, which is the exact problem the product's flagship feature — a tenant-wide agent inventory — was built to solve.
What shipped, and what it costs
Agent 365 is Microsoft's control plane for agents: a registry, a permissions view, activity and risk signals, and a set of admin actions, sitting on top of the identity that Entra Agent ID supplies. It came out of preview on 1 May 2026. Standalone it is $15 per user per month; it is also folded into the Microsoft 365 E7 bundle at $99 per user per month alongside E5, Copilot and the Entra Suite.
The billing unit is the part worth pausing on. The licence is per person — the human who owns, sponsors, manages or is served by an agent — not per agent. Microsoft is explicit that there is no per-agent governance fee, so the cost of the control plane scales with headcount and not with how many agents that headcount creates.
Two capabilities landed on top of that in the weeks since. A Shadow AI view in the Microsoft 365 admin center discovers unmanaged local agents an employee installed on their own — the documentation's own example is OpenClaw — and offers a one-click block that writes an Intune policy out to managed devices. And on 18 August 2026, multi-tenant agent management entered public preview, giving a partner or a group IT function one consolidated list of agents across every tenant it administers, with permissions review and blocking from the same screen.
| Capability | Status | Billing unit | Reach |
|---|---|---|---|
| Agent inventory & governance | GA, 1 May 2026 | $15 / user / month | Agents with an identity in your tenant |
| Shadow AI discovery & block | Public preview | Included | Intune-enrolled managed Windows devices |
| Multi-tenant agent management | Public preview, 18 Aug 2026 | Included | Tenants you administer |
| Fully autonomous agents | Frontier preview | Per agent instance | Agents with their own identity and mailbox |
A flat bill is a missing signal
Take a 500-seat company. Fully licensed, Agent 365 costs $7,500 a month. At fifty agents that is $150 per agent per month of governance; at five thousand it is a dollar fifty. Nothing on the invoice distinguishes the two situations, and nothing on the invoice ever will.
Per-seat pricing is the friendliest shape a vendor can offer here, and the reasoning behind it is sound: charging per agent would tax the behaviour Microsoft wants — registering agents rather than hiding them — and a governance tool that penalises disclosure gets routed around. Given the choice between an accurate meter and a complete inventory, Microsoft picked the inventory. That is the right call.
It is still worth naming what the choice costs, because cost is the only fleet-size feedback most organisations have ever had. Nobody ran a cleanup of unused SaaS integrations out of tidiness; they ran it because a renewal quote arrived with a number on it. Agents get no such letter. An agent built for a quarterly campaign that ended in March keeps its identity, its permissions and its tool access indefinitely, and the only thing that will ever surface it is a person deciding to look. The consequence is not a budget problem — the licence is cheap. It is that the population your inventory and registry has to enumerate, and your security team has to reason about, now grows without producing a single signal anywhere in finance.
So build the brake yourself. Every registered agent gets a named owner, a stated purpose and an expiry date, and expiry means deactivation rather than a ticket. This is boring and it is the whole of the discipline: the reason old service accounts are a perennial audit finding is that nothing ever forced anyone to close them either.
The licence has a topology baked into it
Pricing per human only works if every agent has a human. The licence is written that way on purpose — it covers agents acting on behalf of a licensed user — and for the Copilot-shaped agent that lives in someone's Teams sidebar, that is an accurate description of the world.
It is not an accurate description of the agents that generate the hard governance questions. A nightly reconciliation agent has no sponsor watching it run. A service-account agent wired into a data pipeline is not acting on behalf of the engineer who deployed it eighteen months ago. An agent that spawns sub-agents multiplies principals without multiplying seats. A partner's agent that reaches your tenant over A2A has a human somewhere, but not one of yours. These are the runs that go wrong unattended, and they are precisely the runs whose accountability chain the per-user model cannot express.
Microsoft is not pretending otherwise. Fully autonomous agents — ones with their own identity and their own mailbox — sit in a separate Frontier preview programme licensed per agent instance, with GA pricing not yet announced. There are two pricing models because there are two topologies, and only the sponsored one is generally available. If your roadmap contains unattended agents, and most roadmaps do, the meter that will eventually scale with your fleet is the one still in preview. Get a line item for it into next year's budget before someone else discovers it for you.
The deeper version of this is not about Microsoft at all. Governance frameworks keep reaching for a human principal because that is what every existing control — Conditional Access, DLP, audit review, joiner-mover-leaver — was designed around. An agent with no sponsor breaks the schema rather than the rule, which is the same observation our page on ambient authority arrives at from the credential side.
You can see more machines than you can reach
Shadow AI discovery is the feature that will get demoed, and it is the one to read the footnotes on. Detection and blocking apply to managed Windows devices enrolled in Intune. The block itself is an Intune policy — the docs' worked example creates one named for the agent it stops — which is a clean mechanism with a hard boundary: it lands wherever Intune lands, and nowhere else.
Enumerate what that leaves out and the list is not exotic. A developer's personal Mac. An unmanaged Linux workstation. A CI runner. A container in your own cloud. A contractor's laptop. A phone. Every one of those can run a local agent against corporate data, none of them shows up in the discovery view, and none of them receives the policy. The completeness of your agent inventory is bounded above by the completeness of your device enrolment, and most organisations already know that number and would rather not put it in a slide.
An incomplete inventory is normal and fine — until it is used as evidence. The failure mode is not the gap; it is a governance review that treats "12 agents, all managed" as a finding rather than as a reading taken through a particular instrument. Publish the denominator next to the count. "12 agents discovered across 78% device enrolment" is a sentence an auditor can price; "12 agents" is one they will believe.
Note too what the block button does and does not settle. Blocking an unapproved agent stops a binary from running on an enrolled device. It says nothing about the approved agent that runs inside your tenant with an inherited permission set nobody has reviewed — the content it can reach, the sites it can read, the connectors it was granted at install. Agent 365 governs the agent; it does not govern the tenant underneath the agent, and that second job is still yours.
What to actually do
Buy it if you are on Microsoft 365, and do not oversell it internally. A tenant-wide agent registry with permissions visibility is worth $15 a seat, and building one yourself is a multi-quarter project you would rather not staff. What it is not is a completed governance programme, and the gap between those two readings is where the next audit finding lives.
Give every agent an owner and an expiry on day one. The bill will never ask you to prune, so the register has to. Deactivation on expiry, renewal by a human who states the purpose again — the same lifecycle you already run for service accounts, for the same reason.
Publish enrolment coverage next to the agent count. Any number that comes out of Shadow AI is a lower bound with a known denominator. Reporting it without the denominator converts a useful signal into a false assurance.
Budget for the per-instance meter now. Unattended agents are priced per agent instance and are still in preview. That is the line that scales with your fleet, and it is the one nobody has forecast. Fold it into your spend forecast as a range while the pricing is unknown, rather than as a zero.
Review the permissions the agent inherited, not just the agent. An approved agent with an over-broad connector grant is a bigger exposure than an unapproved agent on a laptop, and only one of the two has a button. Run that review against the tenant on a schedule, using the same scoping discipline as scoped credentials.
FAQ
Does Agent 365 charge per agent?
No. The licence is $15 per user per month, covering the humans who own, sponsor, manage or are served by agents, and Microsoft states there is no per-agent governance fee. The exception is the Frontier preview for fully autonomous agents with their own identities, which is licensed per agent instance with GA pricing not yet announced.
Do I need an Agent 365 licence just to see the agent list?
Viewing the inventory in the Microsoft 365 admin center needs an appropriate admin role rather than a specific licence. The risk and activity signals — the part that tells you what an agent has been doing — are what the Agent 365 licence unlocks. Plan on the licence, because an inventory without activity is a list, not a control.
Can it detect agents on Macs and Linux machines?
Shadow AI detection and blocking currently apply to managed Windows devices enrolled in Intune. Anything outside that enrolment — personal machines, Linux workstations, CI runners, containers — is neither discovered nor blocked, so treat the count as a lower bound over your enrolled estate.
Is per-user pricing bad?
It is the right choice for adoption and a poor source of feedback. Charging per agent would push teams to hide agents from the very registry that makes them governable. The trade-off is that fleet growth becomes invisible in finance, so the pruning discipline has to come from your register instead of from a renewal quote.
Does this replace the identity work in Entra?
No. Entra Agent ID remains the identity foundation; Agent 365 is the registry and control plane on top of it. An agent still needs an identity before there is anything to inventory, permission or revoke, which is why the identity layer is the prerequisite rather than the substitute.
Further reading
On this wiki:
- Agent inventory & registry — what a registry has to record to be worth keeping.
- Accountability & roles — who answers for an agent with no sponsor.
- Agent identity & permissions — the layer underneath the control plane.
- Cost attribution & budgets — how to build the signal the licence does not send.