Understanding Agent 365 Hands On: Managing and Securing AI Agents with Microsoft's Graham Hosking

Graham Hosking, Senior AI Solutions Engineer at Microsoft looking after software developers and ISVs across Europe, takes a demo-led walk through Agent 365 — how it registers, observes and secures agents built in Microsoft platforms, in pro-code frameworks like LangChain, and on Amazon, Google, Data

Understanding Agent 365 Hands On: Managing and Securing AI Agents with Microsoft's Graham Hosking

Prefer audio?

Who should listen: M365 service owners, security and compliance leads, and UC architects who need to inventory, govern and monitor AI agents across Microsoft and non-Microsoft platforms — and anyone building the business case for the E5 to E7 step-up.

Guest: Graham Hosking — Senior AI Solutions Engineer, Microsoft

Graham Hosking, Senior AI Solutions Engineer at Microsoft looking after software developers and ISVs across Europe, takes a demo-led walk through Agent 365 — how it registers, observes and secures agents built in Microsoft platforms, in pro-code frameworks like LangChain, and on Amazon, Google, Databricks and Salesforce. He also covers the licensing model, MCP plugin governance, local agent monitoring, and shows Morgan, a fully autonomous digital CFO with voice and avatar interaction.

Many thanks to Crestron, sponsor of this episode.

Key insights

  • There are two distinct agent classes to govern: 'on behalf of' agents (Copilot, Foundry, Scout in Frontier today) that inherit the signed-in user's permissions, and fully autonomous agents that have their own Entra ID, agent ID, registry entry, mailbox, system and data access, and memory. The security model and licensing conversation is different for each. ▶ 9:48
  • Hosking's own tenant produced a real Defender incident on an agent he had built: Defender reported prompt manipulation techniques being used to invoke an available tool with harmful impact, classified as indirect prompt injection at low risk. The root cause was a recursive loop where his agent prompted another agent, which then triggered tool actions — behaviour he says he would never have seen without the observability layer. ▶ 15:24
  • Agent-to-agent traffic breaks the old trust assumption. Once a marketing agent calls a research agent which calls a video agent — potentially a Microsoft agent calling a Google one — there is no human in the chain deciding what gets passed between them, which is the core argument for central mapping and monitoring. ▶ 17:26
  • The Agent 365 registry can pull in third-party platforms — Amazon, Google, Databricks and Salesforce are supported today, configured with region, project ID and access keys. Crucially, that connection only surfaces the agents and their metadata; it does not give you observability inside them. Hosking's demo tenant held 386 agents; some customers already have 5,000–6,000. ▶ 19:00
  • Observability requires the Agent 365 SDK in the agent. Anything built in Agent Builder, Copilot Studio or hosted in Foundry has it by default; pro-code and third-party agents need it infused. A growing list of ISVs — Adobe, Atlassian, Lovable, Manus — already ship with it, and the supported list is published on the 365 Showcase page. Worth adding 'do you integrate with Agent 365?' to ISV selection criteria. ▶ 20:03
  • Licensing is end-user based, not admin based: any user interacting with an agent that is being observed needs an Agent 365 licence. One licence lights up the whole interface (without it, agent runtime and risk panes are greyed out), but that does not make you compliant, and there is no technical enforcement — the same legal-rather-than-technical model as Purview. E5 is the practical prerequisite, with a step-up path from E5 to E7 rather than repurchasing licences. ▶ 27:40
  • Local, machine-resident agents are covered through Defender for Endpoint — OpenClaw detection is in Frontier now, with more third-party vendors to follow. A practical shadow-IT control if you suspect staff are experimenting with local agents on corporate devices. ▶ 32:44
  • MCP tools and plugins for Copilot Cowork get their own central repository: admins can block a plugin at tenant level, inspect every tool on an MCP server, read the associated skills (natural-language markdown files) to vet them, and scope release to all users, no users, or specific users and groups — useful where an MCP connects to a platform only part of the org is licensed for. Note the Copilot Studio gap: blocked connectors still appear in the thousands-long list to end users, who only discover the block by clicking. ▶ 33:45
  • For autonomous agent design, Hosking uses the rule 'autonomous internally, gated externally' — Morgan, his digital CFO, is actually eight agents, and every financial decision or external communication is gated for human approval while internal reasoning runs freely. ▶ 39:24

Insights summarised by AI from the episode transcript, reviewed by the Empowering.Cloud team.

Listen: Apple Podcasts · Spotify · Other platforms