Governance guide

How to govern Security in Microsoft Agent 365

A step-by-step guide to governing Security in Microsoft Agent 365 with Rencore: detect, review by owner and severity, and remediate with an audit trail.

Definition

Governing Security in Microsoft Agent 365 means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Microsoft Agent 365 with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Security.

Steps

  1. Inventory Microsoft Agent 365

    Connect Microsoft Agent 365 and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Security in Microsoft Agent 365 to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Microsoft Agent 365 reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Microsoft Agent 365 controls for Security

Grounded in the Rencore catalog. See the full Microsoft Agent 365 catalog on the Microsoft Agent 365 connector page.

  • Blocked Agent Still Deployed

    Flags agents that are blocked in the agent registry but still appear deployed to users, indicating that the block is not being enforced.

    Severity: High
  • Shadow AI agent detected on managed devices

    Flags unapproved AI tools and agents detected on Intune-managed devices.

    Severity: Medium
  • Shadow AI: agentic AI CLI detected

    Flags unapproved local agentic AI CLIs and coding agents on managed devices - the highest-risk shadow AI class.

    Severity: High
  • Microsoft-Disabled Blueprint Has Active Identities

    Flags blueprints disabled by Microsoft that still have linked agent identities.

    Severity: High
  • Blueprint Uses Password Credential

    Flags agent identity blueprints that have at least one passwordCredential. Federated identity credentials are preferred for production agents.

    Severity: Medium
  • Microsoft-Disabled Identity Still Enabled

    Flags agent identities that Microsoft disabled (DisabledDueToViolationOfServicesAgreement) but whose account is still enabled in the tenant.

    Severity: High
  • Identity is active (likelihood)

    Risk-probability factor: agent identities that are enabled and not disabled by Microsoft are reachable and therefore carry baseline likelihood for latent risks to surface.

    Severity: Medium
  • Identity has no owners (likelihood)

    Risk-probability factor: identities without a registered owner have no accountability, so misuse or drift goes unnoticed.

    Severity: High
  • Identity holds 5+ application permissions (likelihood)

    Risk-probability factor: a broad set of application permissions widens the attack surface and increases the likelihood that one of them is misused.

    Severity: Medium
  • Identity holds 5+ delegated permissions (likelihood)

    Risk-probability factor: a broad set of delegated permissions widens the on-behalf-of attack surface.

    Severity: Medium
  • Blueprint uses password credential (likelihood)

    Risk-probability factor: blueprints with at least one passwordCredential are materially more likely to suffer a credential leak than federated-only blueprints.

    Severity: High
  • Blueprint has no owners (likelihood)

    Risk-probability factor: blueprints without an owner have no accountability surface, raising the likelihood of unnoticed drift.

    Severity: High
  • Agent user is enabled (likelihood)

    Risk-probability factor: enabled agent user accounts can sign in and act across workloads, so latent issues are likelier to manifest.

    Severity: Medium
  • Agent package is not blocked (likelihood)

    Risk-probability factor: agent packages that are not blocked are usable by end users, so any latent risk in the agent carries baseline likelihood of surfacing.

    Severity: Medium
  • High-privilege permission scope (likelihood)

    Risk-probability factor: high-privilege scopes (.ReadWrite.All, .FullControl.All, .Write.All, Mail.Send, Directory.ReadWrite*, RoleManagement.ReadWrite*) carry elevated likelihood of broad impact when any agent holds them.

    Severity: High
  • Microsoft-disabled identity still enabled (likelihood)

    Risk-probability factor: an identity Microsoft flagged but the tenant left enabled is both suspected and reachable, the highest-likelihood state for an incident to surface.

    Severity: High
  • Identity has a deactivated owner or sponsor (likelihood)

    Risk-probability factor: an identity whose owner or sponsor account is disabled has no functioning oversight, raising the likelihood that drift or misuse goes unnoticed.

    Severity: Medium
  • Blocked Agents

    Lists agents that are currently blocked in the tenant agent registry.

  • Microsoft-Disabled Blueprints with Active Identities

    Lists agent blueprints that Microsoft has disabled but that still have linked agent identities.

  • Blueprints Using Password Credentials

    Lists agent blueprints that have at least one passwordCredential (client secret). Federated identity credentials are preferred for production agents.

Explore the full Microsoft Agent 365 governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern