ADAM PULSE Knowledge Base
Microsoft 365 · Entra · Copilot · Shadow AI

How to secure AI agents connected to Microsoft 365

Short answer

Treat every AI agent that can read or write Microsoft 365 as a principal in Entra, not as a feature toggle. Give it a unique identity, a named owner, an allowlist of tools, and a revoke path that invalidates tokens. Review OAuth grants the same way you review standing mailbox access. Use Microsoft’s Shadow AI admin-center page if you have the license — and do not treat it as the inventory. Use Purview DLP for Copilot where it exists, and read the documented limits before you brief the board that “DLP covers AI.”

This is the Microsoft 365 cut of AI agent security for business. It is risk management, not a CMMC Level 2 or FedRAMP certificate. Menu names and SKUs change; the Learn pages in the references control.

Copilot is already on and nobody has reviewed grants

That is the first Tuesday job: Entra enterprise applications and consent, not a new model. If you cannot yet say which meeting bots have mail or calendar access, start with the private Shadow AI Assessment, then pull the grant list.

Run the assessment →

Entra identity: agents as principals

Microsoft documents agent identities as a distinct construct in Entra: a special service principal created from an agent identity blueprint, used so an agent can request tokens, receive tokens, or act on behalf of a signed-in user with the agent as actor. Agent identities do not carry their own passwords; the blueprint holds credentials. That is the opposite of a shared mailbox and the opposite of “run as whoever clicked Copilot.”

Microsoft 365 Copilot prompts still run in the security context of the user who initiated the prompt (Purview DLP Learn page). That is a different principal from an autonomous agent with tools. Do not collapse them:

Least privilege for AI agents names the failure modes: identity ambiguity, permission creep, over-broad tool access, weak audit trails, and slow revocation. The metric Microsoft cares about for the last one is mean time to revoke or disable the agent identity, including token invalidation.

Do not mix the two Microsoft surfaces. Entra Agent ID is generally available as the identity foundation (authenticate, Conditional Access, owners/sponsors). Microsoft Agent 365 is the unified registry in the Microsoft 365 admin center (Agents > All agents): discover and manage Microsoft and non-Microsoft agents, including agents that do not yet have an Entra Agent ID. The Entra admin center still manages identities for agents that have Agent ID. Viewing the All-agents inventory needs a role such as AI Reader; applying Conditional Access still needs Entra Agent ID licensing. Menu names change; those Learn pages control.

Least privilege in the tenant

Do this in the platform, not in a Copilot instruction file.

  1. Unique identity, named owner/sponsor and approver, documented purpose and tool list.
  2. Task-scoped roles. Separate read (retrieve, summarize) from write (create ticket, send mail, update a record).
  3. Deny unreviewed tools, plugins, and cross-tenant paths by default.
  4. Re-validate authorization at every hop: orchestrator → tool → Exchange / SharePoint / Graph. Do not rely on the orchestrator alone.
  5. Time-bound elevation (PIM or equivalent) for destructive actions. Standing tenant-wide roles are how pilots become production accidents.

The general argument, including OWASP MCP examples, is AI agent permissions and least privilege explained.

Shadow agents: one feed, not the inventory

As of this August 2026 review, Microsoft documents Shadow AI in the Microsoft 365 admin center as a Frontier preview. Prerequisites Microsoft lists include opting into Frontier, Microsoft Defender for Endpoint for local-agent detection, Microsoft 365 E5 to view Shadow AI agents, Intune enrollment for managed Windows, and (for traffic metadata) Global Secure Access. Blocking currently applies to managed Windows devices enrolled in Intune. Microsoft’s published table shows detection for several desktop agents (including ChatGPT Desktop, Claude Desktop, Ollama Desktop) and blocking available for OpenClaw.

Use it if you have the license. Do not treat it as a complete Shadow AI inventory. It does not see a personal ChatGPT tab on a phone, a contractor’s home PC, or a meeting bot that only exists as an OAuth grant. How to find those: What is Shadow AI and how do you find it?

Microsoft’s Cloud Adoption Framework also names shadow AI proliferation and unused (dormant) agents as operational risks when you manage agents across the organization. Dormant is an inventory state: named owner, last-used date, disable if nobody will claim it.

OAuth grants are identity events

Meeting bots, calendar assistants, and “summarize my inbox” apps rarely show up as a blocked domain. They show up as consent. In Entra:

Revoke anything with no named owner. A bot that joined ten calendars last night is an identity event, not an IT anecdote. Put new high-privilege grants on the same change path as a new vendor.

Purview and DLP, as available

Microsoft Purview DLP has a dedicated location: Microsoft 365 Copilot and Copilot Chat (Learn page dated 2026). Documented capabilities, with licensing and roles on that page:

Limits you should say out loud:

Labels and DLP catch a lot of well-intentioned desktop use. They are not the program. Classification, approved-tool lists, and discovery still sit underneath. This article does not use health-record examples; if you are a covered entity, your existing privacy program owns that mapping.

A sequence that survives contact with a real tenant

  1. Inventory Copilot SKUs, Agent 365 (All agents), Entra Agent ID principals, and OAuth grants. Write them on the living list: enterprise AI inventory. All agents is the registry; Agent ID is the identity. Neither is the OAuth-grant list.
  2. Restrict user consent. Stand up admin consent. Revoke orphans.
  3. Turn on the Copilot DLP location for the data classes you already use, inside the documented limits.
  4. If licensed, open Shadow AI (Frontier) and treat it as one feed.
  5. Do not grant an agent send/write until it has a unique identity, an allowlist, HITL in the orchestrator, tool-call logs, and a tested revoke including tokens.

Frequently asked questions

Does Microsoft’s Shadow AI page show every unsanctioned chatbot?

No. As of this August 2026 review, Shadow AI in the Microsoft 365 admin center is a Frontier preview for unsanctioned local AI agents on Intune-managed Windows devices, with Microsoft Defender for Endpoint used for detection. Viewing listed agents requires Microsoft 365 E5. Blocking currently applies only to managed Windows and, in the published table, is available for OpenClaw. It does not see a personal ChatGPT tab on a phone.

Does Purview DLP cover every AI agent in the tenant?

No. Microsoft documents a Microsoft 365 Copilot and Copilot Chat DLP location that can block sensitive prompts, restrict web search, and exclude labeled files from grounding. Selecting that location disables other locations in the same policy. DLP does not inspect files uploaded directly into a prompt. Licensing, roles and rollout timing are on the Learn page. It does not reach consumer Copilot or a personal ChatGPT account.

Should an agent run as the user who clicked it?

Microsoft’s documented pattern is a unique agent identity (Entra Agent ID) with a named owner, not a shared mailbox and not a standing service principal borrowed from a pilot. Copilot prompts still run in the security context of the user who initiated them. Those are different principals. Do not collapse them.

Does securing Copilot certify us for CMMC or FedRAMP?

No. Tenant controls are risk management, not a certificate. They do not make the organization CMMC Level 2 certified or FedRAMP authorized.

What is the first Tuesday job if Copilot is already on?

Review OAuth grants and enterprise-app consent: meeting bots, calendar assistants, and summarize-my-inbox apps. Restrict user consent in Entra, stand up an admin-consent workflow, and revoke grants with no named owner. Then check whether any production agent has a unique identity and an allowlist.

Can we rely on Copilot’s model to refuse a disallowed action?

No. Never rely on the model to enforce permissions. Put least privilege in Entra roles, tool allowlists, and downstream authorization. The twelve-safeguard pillar is the general argument; this page is the Microsoft 365 cut.

Does DLP stop a user pasting a contract into consumer ChatGPT?

Not this DLP location. Purview Copilot DLP evaluates Copilot and Copilot Chat interactions in the tenant. A personal chatbot on an unmanaged device is a Shadow AI and network-path problem, not a Copilot-location policy miss.

Is Entra Agent ID required before we turn Copilot on?

Copilot Chat for a signed-in user is not the same as an autonomous agent with tools. Use Agent ID (or an equivalent unique principal) before an agent can send, write, pay or delete. Do not block a read-only Copilot pilot on that requirement; do not skip it for anything that acts.

References

Microsoft Learn pages were checked in August 2026. Preview features and SKUs change; the live Learn page controls.

  1. Microsoft Learn — Agent identities— Entra Agent ID as a first-class principal; blueprint-held credentials.
  2. Microsoft Learn — What’s new in Microsoft Entra Agent ID (dated 1 May 2026)— Agent ID generally available; registry experiences converging under Agent 365.
  3. Microsoft Learn — Agent Registry convergence with Microsoft Agent 365— All agents in the Microsoft 365 admin center versus identity management in Entra.
  4. Microsoft Learn — Least privilege for AI agents (updated 14 July 2026)— identity, scope, tool allowlists, audit fields, kill-switch metric.
  5. Microsoft Learn — Shadow AI in the Microsoft 365 admin center (updated 25 August 2026)— Frontier preview; E5; Intune; Defender for Endpoint; blocking limits.
  6. Microsoft Learn — Manage AI agents across your organization— shadow AI proliferation and unused agents as operational risks.
  7. Microsoft Learn — Configure user consent settings— Entra user-consent options.
  8. Microsoft Learn — Detect and remediate illicit consent grants— audit-log activity “Consent to application.”
  9. Microsoft Learn — Purview DLP for Microsoft 365 Copilot and Copilot Chat— location capabilities and limits, including uploaded files not scanned.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and Microsoft 365-adjacent operations, SDVOSB. Agent security in a tenant is identity, consent and a path you can see — not a Copilot prompt. This is not a CMMC or FedRAMP certificate. Support: (888) 989-4872 · support@adampulse.us