Adopt Microsoft Agent 365 as our agent control plane?
Microsoft Agent 365 costs $15 per user monthly and splits governance between Foundry and Agent 365, but autonomous agent loops can trigger a 5x cost increase and introduce data leak vulnerabilities.
The question
Every M365 tenant now has to decide whether to standardize agent governance on Microsoft Agent 365 — paying $15/user/mo for a control plane we don't operate — or roll our own agent registry, identity, and access-control infrastructure.
Counsel's position
Standardize on Microsoft Agent 365 to rapidly secure and govern AI agent proliferation, accepting its cost and control limitations.
Verdict
The verdict: Standardize on Microsoft Agent 365 to rapidly secure and govern AI agent proliferation, accepting its cost and control limitations.
Agent 365 costs $15 per user monthly and discovers local shadow agents
Given your decision on agent governance, Agent 365 provides a centralized registry and policy engine for both cloud and local agents.
Microsoft splits agent governance between Foundry for builders and Agent 365 for IT
Standardizing on Microsoft's ecosystem means adopting a dual-control plane strategy where Agent 365 handles organizational governance while Foundry handles development.
Usage-based agent billing triggered a 5x cost increase in one month
While evaluating managed vs. self-hosted infrastructure, consider that autonomous agent loops can rapidly drain shared credit pools under usage-based billing.
Managed governance platforms ship primitives but leave policy authorship to you
Whether you buy Agent 365 or build your own registry, your institution remains responsible for defining the policies those controls enforce.
Microsoft's Autopilot agents introduce prompt injection and data leak vulnerabilities
Relying on Microsoft's managed agents requires accepting the security risks inherent in their underlying OpenClaw architecture.
Read another verdict
- Buy a tool for this process, or build around our own knowledge?
- Our documents are a mess. Clean them up before AI, or after?
- How do we measure the return on an AI workflow — and what baseline is honest?
- Our best people's know-how isn't written down — can AI even use it?
- Automate this workflow, or redesign it before we automate?
- Which process should we point AI at first?
- Our AI pilot works but nobody uses it — fix the workflow or kill it?
- Rent AI from a vendor, or run your own?