Adopt Microsoft Agent 365 as our agent control plane?
Microsoft Agent 365 costs $15 per user monthly and splits governance between Foundry and Agent 365, but autonomous agent loops can trigger a 5x cost increase and introduce data leak vulnerabilities.
The question
Every M365 tenant now has to decide whether to standardize agent governance on Microsoft Agent 365 — paying $15/user/mo for a control plane we don't operate — or roll our own agent registry, identity, and access-control infrastructure.
Counsel's position
Standardize on Microsoft Agent 365 to rapidly secure and govern AI agent proliferation, accepting its cost and control limitations.
Verdict
The verdict: Standardize on Microsoft Agent 365 to rapidly secure and govern AI agent proliferation, accepting its cost and control limitations.
How the criteria decide
3 of 3 criteria resolved on cited evidence.
| Criterion | Favours | Evidence |
|---|---|---|
| Microsoft Agent 365 adoption decision | Standardize on Microsoft Agent 365 | Agent 365 costs $15 per user monthly and discovers local shadow agents discover and manage local AI agents — the tools that developers and knowledge workers are installing directly on their Windows devices Microsoft splits agent governance between Foundry for builders and Agent 365 for IT Foundry Control Plane is primarily for the teams that build and operate agents. Agent 365 is primarily for the teams that govern agents. Microsoft Foundry Blog articles Managed governance platforms ship primitives but leave policy authorship to you The controls shipped this year; the judgement about what they should enforce, and the accountability for the result, stayed where they have always been. |
| agent registry, identity, and audit architecture | Standardize on Microsoft Agent 365 | Agent 365 costs $15 per user monthly and discovers local shadow agents discover and manage local AI agents — the tools that developers and knowledge workers are installing directly on their Windows devices Microsoft splits agent governance between Foundry for builders and Agent 365 for IT Foundry Control Plane is primarily for the teams that build and operate agents. Agent 365 is primarily for the teams that govern agents. Microsoft Foundry Blog articles Managed governance platforms ship primitives but leave policy authorship to you The controls shipped this year; the judgement about what they should enforce, and the accountability for the result, stayed where they have always been. |
| vendor-platform vs roll-your-own trade-offs for AI infra | Standardize on Microsoft Agent 365 | Agent 365 costs $15 per user monthly and discovers local shadow agents discover and manage local AI agents — the tools that developers and knowledge workers are installing directly on their Windows devices Usage-based agent billing triggered a 5x cost increase in one month triggered a massive 5x cost increase in a single month. Managed governance platforms ship primitives but leave policy authorship to you The controls shipped this year; the judgement about what they should enforce, and the accountability for the result, stayed where they have always been. |
Agent 365 costs $15 per user monthly and discovers local shadow agents
Given your decision on agent governance, Agent 365 provides a centralized registry and policy engine for both cloud and local agents.
Microsoft splits agent governance between Foundry for builders and Agent 365 for IT
Standardizing on Microsoft's ecosystem means adopting a dual-control plane strategy where Agent 365 handles organizational governance while Foundry handles development.
Usage-based agent billing triggered a 5x cost increase in one month
While evaluating managed vs. self-hosted infrastructure, consider that autonomous agent loops can rapidly drain shared credit pools under usage-based billing.
Managed governance platforms ship primitives but leave policy authorship to you
Whether you buy Agent 365 or build your own registry, your institution remains responsible for defining the policies those controls enforce.
Microsoft's Autopilot agents introduce prompt injection and data leak vulnerabilities
Relying on Microsoft's managed agents requires accepting the security risks inherent in their underlying OpenClaw architecture.
Read another verdict
- Which process should we point AI at first?
- Put one person in charge of AI — or is a Head of AI premature for us?
- Buy a tool for this process, or build around our own knowledge?
- Centralize AI strategy under CEO or distribute ownership?
- Adopt new AI ROI tools or refine existing methods?
- Invest in pre-build costing or post-deployment ROI tracking?
- Our documents are a mess. Clean them up before AI, or after?
- How do we measure the return on an AI workflow — and what baseline is honest?