 {"id":519052,"date":"2025-08-04T10:41:11","date_gmt":"2025-08-04T17:41:11","guid":{"rendered":"https:\/\/jorgep.com\/blog\/?p=519052"},"modified":"2026-02-18T13:02:12","modified_gmt":"2026-02-18T20:02:12","slug":"ai-agents-in-microsoft-365-a-simple-guide-to-agent-governance","status":"publish","type":"post","link":"https:\/\/jorgep.com\/blog\/ai-agents-in-microsoft-365-a-simple-guide-to-agent-governance\/","title":{"rendered":"AI Agents in Microsoft 365: A Simple Guide to Agent Governance"},"content":{"rendered":"\n<div class=\"wp-block-columns has-theme-palette-7-background-color has-background is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p>Part of: <strong> <a href=\"https:\/\/jorgep.com\/blog\/series-ai-learnings\/\">AI Learning Series Here<\/a><\/strong><\/p>\n\n\n<style>.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col,.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col:before{border-top-left-radius:0px;border-top-right-radius:0px;border-bottom-right-radius:0px;border-bottom-left-radius:0px;}.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col{column-gap:var(--global-kb-gap-sm, 1rem);}.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col{flex-direction:column;}.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col > .aligncenter{width:100%;}.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col:before{opacity:0.3;}.kadence-column395113_43ef2d-d5{position:relative;}@media all and (max-width: 1024px){.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}@media all and (max-width: 767px){.kadence-column395113_43ef2d-d5 > .kt-inside-inner-col{flex-direction:column;justify-content:center;}}<\/style>\n<div class=\"wp-block-kadence-column kadence-column395113_43ef2d-d5\"><div class=\"kt-inside-inner-col\"><style>.wp-block-kadence-advancedheading.kt-adv-heading510545_6813a5-28, .wp-block-kadence-advancedheading.kt-adv-heading510545_6813a5-28[data-kb-block=\"kb-adv-heading510545_6813a5-28\"]{font-size:var(--global-kb-font-size-sm, 0.9rem);font-style:normal;}.wp-block-kadence-advancedheading.kt-adv-heading510545_6813a5-28 mark.kt-highlight, .wp-block-kadence-advancedheading.kt-adv-heading510545_6813a5-28[data-kb-block=\"kb-adv-heading510545_6813a5-28\"] mark.kt-highlight{font-style:normal;color:#f76a0c;-webkit-box-decoration-break:clone;box-decoration-break:clone;padding-top:0px;padding-right:0px;padding-bottom:0px;padding-left:0px;}.wp-block-kadence-advancedheading.kt-adv-heading510545_6813a5-28 img.kb-inline-image, .wp-block-kadence-advancedheading.kt-adv-heading510545_6813a5-28[data-kb-block=\"kb-adv-heading510545_6813a5-28\"] img.kb-inline-image{width:150px;vertical-align:baseline;}<\/style>\n<p class=\"kt-adv-heading510545_6813a5-28 wp-block-kadence-advancedheading\" data-kb-block=\"kb-adv-heading510545_6813a5-28\">Quick Links:&nbsp;<a href=\"https:\/\/jorgep.com\/blog\/resources-for-learning-ai\/\">Resources for Learning AI<\/a> | <a href=\"https:\/\/jorgep.com\/blog\/keeping-up-with-ai\/\">Keep up with AI<\/a> | <a href=\"https:\/\/jorgep.com\/blog\/list-of-ai-tools\/\" data-type=\"post\" data-id=\"402818\">List of AI Tools<\/a><\/p>\n<\/div><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-template-part\"><style>.wp-block-kadence-advancedheading.kt-adv-heading395113_c650df-47, .wp-block-kadence-advancedheading.kt-adv-heading395113_c650df-47[data-kb-block=\"kb-adv-heading395113_c650df-47\"]{text-align:center;font-size:var(--global-kb-font-size-md, 1.25rem);line-height:60px;font-style:normal;background-color:#f5a511;}.wp-block-kadence-advancedheading.kt-adv-heading395113_c650df-47 mark.kt-highlight, .wp-block-kadence-advancedheading.kt-adv-heading395113_c650df-47[data-kb-block=\"kb-adv-heading395113_c650df-47\"] mark.kt-highlight{font-style:normal;color:#f76a0c;-webkit-box-decoration-break:clone;box-decoration-break:clone;padding-top:0px;padding-right:0px;padding-bottom:0px;padding-left:0px;}.wp-block-kadence-advancedheading.kt-adv-heading395113_c650df-47 img.kb-inline-image, .wp-block-kadence-advancedheading.kt-adv-heading395113_c650df-47[data-kb-block=\"kb-adv-heading395113_c650df-47\"] img.kb-inline-image{width:150px;vertical-align:baseline;}<\/style>\n<p class=\"kt-adv-heading395113_c650df-47 wp-block-kadence-advancedheading\" data-kb-block=\"kb-adv-heading395113_c650df-47\">Subscribe to <a href=\"https:\/\/go.35s.be\/jtb\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>JorgeTechBits  newsletter<\/strong><\/a><\/p>\n<\/div><\/div>\n<\/div>\n\n\n\n<p>Summary originally generated with Microsoft Copilot <\/p>\n\n\n\n<p>As <a href=\"https:\/\/jorgep.com\/blog\/tag\/ai-agents\/\">AI agents <\/a>become more common in the workplace, especially within Microsoft 365, it&#8217;s crucial to manage them securely and effectively.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>AI agents are transforming how we work\u2014automating tasks, improving decision-making, and enhancing collaboration. But with great power comes great responsibility.   The recently published (last week) <a href=\"https:\/\/adoption.microsoft.com\/files\/copilot-studio\/Agent-governance-whitepaper.pdf\">Microsoft\u2019s <strong>Agent Governance Whitepaper<\/strong> <\/a>lays out a roadmap for IT teams to do just that\u2014without overwhelming complexity. This is not the only guideline out there but it is the first that Microsoft officially produces  as a governance framework that organizations can innovate confidently while keeping data secure and operations compliant.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Everyone involved in AI Agent deployments should read this one in full, but here&#8217;s a breakdown of the key ideas on it:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"whatareaiagentsandwhydotheymatter\"><strong>What Are AI Agents and Why Do They Matter?<\/strong><\/h3>\n\n\n\n<p><strong><em>AI agents in Microsoft 365 <\/em><\/strong>help automate tasks, answer questions, and improve productivity. They can be built using tools like:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SharePoint<\/strong> (based on stored content)<\/li>\n\n\n\n<li><strong>Copilot Studio Agent Builder<\/strong> (for conversational templates)<\/li>\n\n\n\n<li><strong>Full Copilot Studio<\/strong> (for advanced logic and integrations)<\/li>\n\n\n\n<li><strong>Pro Developer Tools<\/strong> (for custom-built agents)<\/li>\n<\/ul>\n\n\n\n<p>The paper, goes on to differentiate the use of agents by different types of users, which is pretty universal:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>End Users<\/strong>: Non-technical staff using simple tools.<\/li>\n\n\n\n<li><strong>Makers<\/strong>: Tech-savvy users building more complex agents.<\/li>\n\n\n\n<li><strong>Developers<\/strong>: Experts creating advanced, secure solutions.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"whygovernanceisessential\"><strong>Why Governance Is Essential<\/strong><\/h3>\n\n\n\n<p>Governance ensures agents are safe, compliant, and effective. Microsoft outlines three main types of controls:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Tool Controls<\/strong>: Limit what agent-building tools can do.<\/li>\n\n\n\n<li><strong>Content Controls<\/strong>: Manage what data agents can access.<\/li>\n\n\n\n<li><strong>Agent Management<\/strong>: Monitor agent usage, performance, and lifecycle.<\/li>\n<\/ol>\n\n\n\n<p>These controls are managed through platforms like the <strong>Microsoft 365 Admin Center<\/strong>, <strong>Power Platform Admin Center<\/strong>, and <strong>Microsoft Purview<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"securityandcompliancetools\"><strong>Security and Compliance Tools<\/strong><\/h3>\n\n\n\n<p>Microsoft provides several tools to keep agents secure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Microsoft Purview<\/strong>: Automatically detects and protects sensitive data.<\/li>\n\n\n\n<li><strong>Data Loss Prevention (DLP)<\/strong>: Blocks agents from accessing confidential files.<\/li>\n\n\n\n<li><strong>Communication Compliance &amp; Audit Logs<\/strong>: Tracks agent interactions to ensure ethical and legal use.<\/li>\n\n\n\n<li><strong>eDiscovery<\/strong>: Helps with legal investigations by reviewing agent activity.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"costmanagementoptions\"><strong>Cost Management Options<\/strong><\/h3>\n\n\n\n<p>Organizations can choose between:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Prepaid licenses<\/strong>: Fixed cost for predictable usage.<\/li>\n\n\n\n<li><strong>Metered billing<\/strong>: Pay-as-you-go based on actual use.<\/li>\n<\/ul>\n\n\n\n<p>This flexibility helps manage budgets while scaling agent deployment.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"gettingstarteda3phaseapproach\"><strong>Getting Started: A 3-Phase Approach<\/strong><\/h3>\n\n\n\n<p>Here&#8217;s the <strong>3-Phase Approach<\/strong> that Microsoft recommends  in their project approach: <\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th><strong>Phase<\/strong><\/th><th><strong>Focus<\/strong><\/th><th><strong>Key Actions<\/strong><\/th><\/tr><\/thead><tbody><tr><td><strong>Phase 1: Build a Champion Team<\/strong><\/td><td>Start small with IT leadership<\/td><td>&#8211; Form a small IT team to test Agent Builder<br>&#8211; Assign licenses and permissions<br>&#8211; Create the first organization-wide agent<\/td><\/tr><tr><td><strong>Phase 2: Train and Expand<\/strong><\/td><td>Educate and empower departments<\/td><td>&#8211; Train departments on safe agent building<br>&#8211; Launch proof-of-concept agents<br>&#8211; Establish a Center of Excellence for governance<\/td><\/tr><tr><td><strong>Phase 3: Deploy and Monitor<\/strong><\/td><td>Scale responsibly<\/td><td>&#8211; Identify and train departmental agent makers<br>&#8211; Set up billing meters and sharing controls<br>&#8211; Monitor usage and spending<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>With the right team, tools, and guardrails, enterprises can unlock real value of AI Agents securely and responsibly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Resources: <\/h2>\n\n\n\n<p>As I mentioned, I encourage you to read the entire paper at: <a href=\"https:\/\/adoption.microsoft.com\/files\/copilot-studio\/Agent-governance-whitepaper.pdf\">Agent Governance Whitepaper<\/a><\/p>\n\n\n\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Read my many other blog posts on <a href=\"https:\/\/jorgep.com\/blog\/tag\/ai-agents\/\">AI Agents Here<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/blog\/healthcareandlifesciencesblog\/mastering-agent-governance-in-microsoft-365\/4416627\">Mastering Agent Governance Episode 6: Getting Started with Agent Governance<\/a><\/li>\n\n\n\n<li>YouTube: (3 month old, but good!) <a href=\"https:\/\/www.youtube.com\/watch?v=51tm_yScyqo&amp;t=2s\">Copilot Agents Governance &#8211; 1 Hour Overview<\/a><\/li>\n\n\n\n<li>Microsoft <a href=\"https:\/\/adoption.microsoft.com\/en-us\/customer-hub\/ai-agents\/\">AI Agents Webinars \u2013 Microsoft Adoption<\/a><\/li>\n\n\n\n<li>Good 3 Part Read on Microsoft Community Hub:   AI Agents Overview by ShivamGoyal03 \n<ul class=\"wp-block-list\">\n<li>Part1:  <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/educatordeveloperblog\/unlocking-the-power-of-ai-agents-an-introductory-guide---part-1\/4387378\">Unlocking the Power of AI Agents: An Introductory Guide <\/a><\/li>\n\n\n\n<li>Part 2: <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/educatordeveloperblog\/ai-agents-exploring-agentic-frameworks---part-2\/4388062\">AI Agents: Exploring Agentic Frameworks<\/a><\/li>\n\n\n\n<li>Part 3: <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/educatordeveloperblog\/ai-agents-key-principles-and-guidelines---part-3\/4390677\">AI Agents: Key Principles and Guidelines<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Have questions ?<\/h3>\n\n\n\n<p>Please feel <a href=\"https:\/\/jorgep.com\/blog\/contact-jorgep\/\">free to reach out<\/a> if you have questions. Happy to answer anything I can.  <br>I work with an amazing team of professionals at Dell Technologies Services.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"font-family: Verdana, Geneva, sans-serif; font-size: 11px; line-height: 1.6; color: #333;\">\n    <p>\n        <strong>Disclaimer:<\/strong> \n        <em>I personally love to share my learnings, thoughts, and ideas; I get great satisfaction knowing someone has read and benefited from an article. This content is created entirely on my own time and in a personal capacity. The views expressed here are mine alone and do not represent the positions or opinions of my employer.<\/em>\n    <\/p>\n    <p>\n        In my professional role, I serve as a Workforce Transformation Solutions Principal for \n        <a href=\"https:\/\/www.dell.com\/en-us\/work\/learn\/by-service-type-deployment\" style=\"color: #007db8; font-weight: bold; text-decoration: none;\">Dell Technology Services<\/a>. \n        I am passionate about guiding organizations through complex technology transitions and \n        <a href=\"https:\/\/www.delltechnologies.com\/en-us\/what-we-do\/workforce-transformation.htm\" style=\"color: #007db8; font-weight: bold; text-decoration: none;\">Workforce Transformation<\/a>. \n        <a href=\"https:\/\/www.delltechnologies.com\/en-us\/index.htm\" style=\"color: #007db8; font-weight: bold; text-decoration: none;\">Learn more at Dell Technologies<\/a>.\n    <\/p>\n    <hr style=\"border: 0; border-top: 1px solid #ddd; margin: 12px 0;\">\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Summary originally generated with Microsoft Copilot As AI agents become more common in the workplace, especially within Microsoft 365, it&#8217;s crucial to manage them securely and effectively. AI agents are transforming how we work\u2014automating tasks, improving decision-making, and enhancing collaboration. But with great power comes great responsibility. The recently published (last week) Microsoft\u2019s Agent Governance&#8230;<\/p>\n","protected":false},"author":2,"featured_media":447242,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","ngg_post_thumbnail":0,"episode_type":"","audio_file":"","podmotor_file_id":"","podmotor_episode_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","itunes_episode_number":"","itunes_title":"","itunes_season_number":"","itunes_episode_type":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[681,441],"tags":[471,941,930,870,871,730,742],"class_list":["post-519052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-moderneuc2","category-tech-talk","tag-ai","tag-ai-agents","tag-ai-series","tag-copilot","tag-genai","tag-microsoft-365","tag-moderneuc1"],"taxonomy_info":{"category":[{"value":681,"label":"ModernEUC"},{"value":441,"label":"Tech Talk"}],"post_tag":[{"value":471,"label":"AI"},{"value":941,"label":"AI Agents"},{"value":930,"label":"AI Series"},{"value":870,"label":"Copilot"},{"value":871,"label":"GenAi"},{"value":730,"label":"Microsoft 365"},{"value":742,"label":"ModernEUC"}]},"featured_image_src_large":["https:\/\/jorgep.com\/blog\/wp-content\/uploads\/ModerndEUC-Copilot11.jpg",600,254,false],"author_info":{"display_name":"Jorge Pereira","author_link":"https:\/\/jorgep.com\/blog\/author\/jorge\/"},"comment_info":0,"category_info":[{"term_id":681,"name":"ModernEUC","slug":"moderneuc2","term_group":0,"term_taxonomy_id":691,"taxonomy":"category","description":"","parent":0,"count":261,"filter":"raw","cat_ID":681,"category_count":261,"category_description":"","cat_name":"ModernEUC","category_nicename":"moderneuc2","category_parent":0},{"term_id":441,"name":"Tech Talk","slug":"tech-talk","term_group":0,"term_taxonomy_id":451,"taxonomy":"category","description":"","parent":0,"count":672,"filter":"raw","cat_ID":441,"category_count":672,"category_description":"","cat_name":"Tech Talk","category_nicename":"tech-talk","category_parent":0}],"tag_info":[{"term_id":471,"name":"AI","slug":"ai","term_group":0,"term_taxonomy_id":481,"taxonomy":"post_tag","description":"","parent":0,"count":144,"filter":"raw"},{"term_id":941,"name":"AI Agents","slug":"ai-agents","term_group":0,"term_taxonomy_id":951,"taxonomy":"post_tag","description":"","parent":0,"count":28,"filter":"raw"},{"term_id":930,"name":"AI Series","slug":"ai-series","term_group":0,"term_taxonomy_id":940,"taxonomy":"post_tag","description":"","parent":0,"count":146,"filter":"raw"},{"term_id":870,"name":"Copilot","slug":"copilot","term_group":0,"term_taxonomy_id":880,"taxonomy":"post_tag","description":"","parent":0,"count":19,"filter":"raw"},{"term_id":871,"name":"GenAi","slug":"genai","term_group":0,"term_taxonomy_id":881,"taxonomy":"post_tag","description":"","parent":0,"count":79,"filter":"raw"},{"term_id":730,"name":"Microsoft 365","slug":"microsoft-365","term_group":0,"term_taxonomy_id":740,"taxonomy":"post_tag","description":"","parent":0,"count":45,"filter":"raw"},{"term_id":742,"name":"ModernEUC","slug":"moderneuc1","term_group":0,"term_taxonomy_id":752,"taxonomy":"post_tag","description":"","parent":0,"count":284,"filter":"raw"}],"_links":{"self":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts\/519052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/comments?post=519052"}],"version-history":[{"count":4,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts\/519052\/revisions"}],"predecessor-version":[{"id":519059,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/posts\/519052\/revisions\/519059"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/media\/447242"}],"wp:attachment":[{"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/media?parent=519052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/categories?post=519052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jorgep.com\/blog\/wp-json\/wp\/v2\/tags?post=519052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}