Agent skill

Microsoft Agent 365

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party)…

MITAuto-check passed

Install Microsoft Agent 365

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill microsoft-agent-365 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills microsoft-agent-365 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/microsoft-agent-365 .claude/skills/microsoft-agent-365 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
microsoft-agent-365
GitHub stars
175
Token cost
~2k tokens
SKILL.md length
925 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party)…

  • Works in 7 steps: Observe - build the inventory - Use the… → Assign identity (Entra Agent ID) -… → Govern lifecycle & access - Onboard… → …
  • Purview-only data controls on a single agent (use purview-agent-365-security)
  • SKILL.md covers When to use, Pick the right pillar for the…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Microsoft Agent 365 is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party) from a single registry, using Microsoft Entra Agent ID for identity, Microsoft Purview for data security, and Microsoft Defender for runtime threat protection. WHEN: Microsoft Agent 365, Agent 365, manage agents at scale, agent control plane, agent registry, agent map, observe govern secure agents, Entra Agent ID…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Microsoft Copilot Studio, Microsoft Defender, Microsoft Entra ID and Microsoft 365. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Purview-only data controls on a single agent (use purview-agent-365-security)
  • End-user Copilot oversharing (use purview-copilot-oversharing)

Example prompts

  • “/microsoft-agent-365”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Observe - build the inventory - Use the Agent 365 agent registry in the Microsoft 365
  2. Assign identity (Entra Agent ID) - Ensure each agent has a managed **Microsoft Entra
  3. Govern lifecycle & access - Onboard agents intentionally with IT oversight, apply
  4. Secure the data (Purview) - Bring agent instances into Microsoft Purview: DSPM for AI for
  5. Apply risk-based access (Conditional Access) - Use Entra Conditional Access so agents and
  6. Defend at runtime (Defender) - Use Microsoft Defender for Cloud Apps real-time agent
  7. Audit & meet regulations - Confirm agent interactions land in Purview Audit / Activity

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Microsoft Agent 365 loads about 2k tokens when it runs. Until then it costs about 203 tokens; SKILL.md has 925 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~203
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 925 words, ~1,999 tokens.

Download SKILL.mdSave it as .claude/skills/microsoft-agent-365/SKILL.md (or your agent's skills folder).
name
microsoft-agent-365
description
Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party) from a single registry, using Microsoft Entra Agent ID for identity, Microsoft Purview for data security, and Microsoft Defender for runtime threat protection. WHEN: Microsoft Agent 365, Agent 365, manage agents at scale, agent control plane, agent registry, agent map, observe govern secure agents, Entra Agent ID, agent identity lifecycle, third-party agent governance, secure AI agents tenant-wide, agent sprawl, agent inventory. DO NOT USE for Purview-only data controls on a single agent (use purview-agent-365-security) or end-user Copilot oversharing (use purview-copilot-oversharing).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Managing AI Agents with Microsoft Agent 365

Microsoft Agent 365 is the control plane for agents - it extends the infrastructure you use to manage people (identity, access, data protection, threat defense) to AI agents, regardless of where they originate (Microsoft, Copilot Studio, partner/third-party including agents built on Anthropic Claude, OpenAI, or Google Gemini, or custom-built). It organises the work into three pillars: observe, govern, and secure. Generally available for Commercial since 1 May 2026, licensed per user, with Microsoft E5 as the recommended prerequisite.

When to use

Standing up enterprise-wide management for a growing fleet of AI agents - when you need a single inventory, consistent lifecycle and access controls, and unified security across agents built on different platforms. Use it as the orchestration layer that ties together Entra, Purview, and Defender for agents.

Do not use this skill for Purview data-security controls on a single agent in isolation (use purview-agent-365-security), or to remediate Microsoft 365 Copilot oversharing of end-user content (use purview-copilot-oversharing / m365-oversharing).

Pick the right pillar for the problem

GoalPillarPrimary surface
Know how many agents exist, who owns them, how they're usedObserveAgent registry + Agent Map in Microsoft 365 admin center
Onboard, approve, review, and retire agents with policyGovernAgent management in M365 admin center + Microsoft Purview
Give each agent a managed identity and risk-based accessSecureMicrosoft Entra Agent ID + Conditional Access
Stop agents leaking or over-accessing sensitive dataSecureMicrosoft Purview (DSPM for AI, DLP, sensitivity labels, IRM)
Detect malicious or unsafe agent behaviour at runtimeSecureMicrosoft Defender for Cloud Apps (real-time agent protection)

Rule of thumb: treat every agent as a first-class, governed identity - not a feature of an app. The more autonomous the agent, the more it must be managed like a privileged account.

Approach

  1. Observe - build the inventory - Use the Agent 365 agent registry in the Microsoft 365 admin center to get a single, centralised view of every agent (Microsoft, Copilot Studio, third-party), its owner, adoption, activity, and health. Use Agent Map to see relationships and access. Verify: the registry lists agents from more than one build platform with named owners.
  2. Assign identity (Entra Agent ID) - Ensure each agent has a managed Microsoft Entra Agent ID so it can be authenticated, authorised, and governed like any other directory identity - not a shared secret or anonymous app. Verify: each production agent resolves to a distinct Entra Agent ID with an owner.
  3. Govern lifecycle & access - Onboard agents intentionally with IT oversight, apply least-privilege access to resources/data, require approvals, and run periodic access reviews; retire low-value or ownerless agents on a cadence. Verify: an agent cannot reach a data source it was not explicitly granted.
  4. Secure the data (Purview) - Bring agent instances into Microsoft Purview: DSPM for AI for visibility, data classification + sensitivity labels, DLP, Insider Risk Management, and Communication Compliance. New Agent 365 agent instances are auto-enabled for audit and sensitive-data detection. Verify: DSPM for AI's AI observability page shows the agent instance and its data risks.
  5. Apply risk-based access (Conditional Access) - Use Entra Conditional Access so agents and the users they act for meet consistent, risk-based access conditions. Verify: a risky context blocks or steps up the agent's access as policy dictates.
  6. Defend at runtime (Defender) - Use Microsoft Defender for Cloud Apps real-time agent protection to detect and block unsafe behaviour, prompt-injection, and malicious activity while the agent runs. Verify: a simulated unsafe action raises a Defender alert / is blocked.
  7. Audit & meet regulations - Confirm agent interactions land in Purview Audit / Activity Explorer and use Compliance Manager AI-regulation assessments to track obligations. Verify: an agent prompt/response appears in unified audit search with agent + user metadata.
Show full SKILL.md (314 more words)Show less

Guardrails

  • Agent 365 is an orchestration layer over Entra, Purview, and Defender - its protection is only as strong as the underlying classification, labelling, and oversharing posture. Fix the data estate first; agents amplify every gap.
  • Treat agent identities as governed, least-privilege identities with owners and renewal cadences. Permanent broad permissions on an agent identity is a future incident.
  • Require security review before tenant-wide publish of any agent, including pre-integrated third-party agents from the admin center.
  • Don't assume capability parity: Purview support varies by capability (for example, encryption without sensitivity labels is not supported for Agent 365 AI interactions). Check the supported matrix before relying on a control.
  • Agent 365 works best with E5 and requires at least one qualifying Agent 365 license - confirm licensing before planning a rollout.
  • Communicate to users that agent interactions are logged and reviewed; get legal/HR sign-off on monitoring scope.

Common anti-patterns

  • No agent inventory - nobody knows how many agents are in production or who owns them.
  • Letting agents run as shared app registrations instead of distinct Entra Agent IDs.
  • Onboarding third-party agents (including Claude-, OpenAI-, or Gemini-based agents) tenant-wide with no DLP, no access scoping, and no review.
  • Skipping runtime detection (Defender) and relying only on build-time policy.
  • Leaving ownerless or low-value agents running - cost and permission-sprawl risk.

Example prompts

  • Set up Microsoft Agent 365 to manage all our AI agents at scale.
  • How do I observe, govern, and secure agents from one control plane?
  • Give each agent an Entra Agent ID and least-privilege access.
  • Use Purview and Defender to secure Agent 365 agents.
  • Build an agent inventory and retire ownerless agents.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/microsoft-agent-365 of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Microsoft Agent 365 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Microsoft Agent 365 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Microsoft Agent 365 this skillvinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
CLI Microsoft365pnp/cli-microsoft365-mcp-server132—~3.5kAutomated safety check: PassMIT
CLI Microsoft365 Scriptpnp/cli-microsoft365-mcp-server132—~3.3kAutomated safety check: PassMIT
Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure2552 repos~4kAutomated safety check: PassMIT
AI Agent ActivitySCStelz/security-investigator249—~17kAutomated safety check: PassMIT
AI Agent PostureSCStelz/security-investigator249—~21kAutomated safety check: PassMIT

Similar skills

  • CLI Microsoft365

    pnp/cli-microsoft365-mcp-server

    Use CLI for Microsoft 365 to manage Microsoft 365 tenants from the terminal.

    132 GitHub stars~3.5k tokensUpdated 5 days ago
    Documents & OfficeAuto-check passed
  • CLI Microsoft365 Script

    pnp/cli-microsoft365-mcp-server

    Write PowerShell scripts using CLI for Microsoft 365 commands to automate Microsoft 365 management tasks.

    132 GitHub stars~3.3k tokensUpdated 5 days ago
    Documents & OfficeAuto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Backend & APIsAuto-check passed
  • AI Agent Activity

    SCStelz/security-investigator

    Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…

    249 GitHub stars~17k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • AI Agent Posture

    SCStelz/security-investigator

    Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.

    249 GitHub stars~21k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • M365 Agents Py

    microsoft/skills

    Official

    Microsoft 365 Agents SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3.5k tokens
    Documents & OfficeAuto-check: notes

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Microsoft Agent 365

What does Microsoft Agent 365 do?

Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party)…. Microsoft Agent 365 is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for managing AI agents at enterprise scale with Microsoft Agent 365 - the control plane that lets admins observe, govern, and secure every agent (Microsoft, Copilot Studio, and third-party) from a single registry, using Microsoft Entra Agent ID for identity, Microsoft Purview for data security, and Microsoft Defender for runtime threat protection.

When should I use Microsoft Agent 365?

Microsoft Agent 365 fits situations like: purview-only data controls on a single agent (use purview-agent-365-security); end-user Copilot oversharing (use purview-copilot-oversharing).

How do I install Microsoft Agent 365 in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill microsoft-agent-365 -a claude-code`. Or copy the skill folder (skills/microsoft-agent-365 in vinayaklatthe/microsoft-security-skills) into .claude/skills/microsoft-agent-365 in your project. Claude Code loads it when a task matches its description.

How do I install Microsoft Agent 365 in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill microsoft-agent-365 -a codex`. Or copy the skill folder (skills/microsoft-agent-365 in vinayaklatthe/microsoft-security-skills) into .agents/skills/microsoft-agent-365 in your project. Codex loads it when a task matches its description.

Can I use Microsoft Agent 365 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill microsoft-agent-365 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/microsoft-agent-365, .gemini/skills/microsoft-agent-365, .github/skills/microsoft-agent-365 and .opencode/skills/microsoft-agent-365 in your project.

What does Microsoft Agent 365 need to run?

SKILL.md names no scripts, command-line tools or credentials: Microsoft Agent 365 is instructions for the agent only.

Does Microsoft Agent 365 access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Microsoft Agent 365 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Microsoft Agent 365 use?

Microsoft Agent 365 is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Microsoft Agent 365 use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Microsoft Agent 365?

Skills that share tags, products or a category with Microsoft Agent 365: CLI Microsoft365 (pnp/cli-microsoft365-mcp-server, 132 stars), CLI Microsoft365 Script (pnp/cli-microsoft365-mcp-server, 132 stars), Entra Agent Id (microsoft/GitHub-Copilot-for-Azure, 255 stars) and AI Agent Activity (SCStelz/security-investigator, 249 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Microsoft Agent 365?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.