AI in Microsoft ERP · Agent Governance Update · Series 4 · #038
Every agent covered in this series — Scout, Cowork, Copilot Studio agents, D365’s own pre-built agents — needs to live somewhere governable. Agent 365 just got a major upgrade as part of Build. Here’s the current state.


Why This Matters More Now Than It Did a Month Ago
Take stock of what’s now live in a typical Microsoft 365 + D365 tenant as of this month: Microsoft’s pre-built D365 agents (Payables Agent, Sales Order Agent, Finance Agent), Copilot Cowork with D365 and Fabric plugins, custom Copilot Studio agents (potentially including voice agents and computer-using agents), and – for Frontier-enrolled organizations – Microsoft Scout. That’s a meaningfully larger agent surface than existed even two months ago, and it’s growing every release cycle.
Each of these agents potentially has access to different data, operates under different identities, and carries different risk profiles. Without a unified governance layer, IT and security teams are tracking this sprawl manually — which doesn’t scale and creates real blind spots.
The Identity Architecture Tying It Together
The architectural pattern Microsoft has standardized across this entire agent ecosystem (and it’s consistent whether you’re looking at Scout, Cowork tasks, or Copilot Studio agents) is that every agent operates under its own governed Entra identity, not a shared or anonymous service account. This means every action an agent takes is attributable to a specific, known actor that your existing identity infrastructure already understands and can apply policy to.
This matters practically: it means the security review process you’d apply to a new employee’s access (what can they see, what can they do, what’s logged) is the same conceptual framework that applies to a new agent. Agent 365 is the place where that review and ongoing oversight actually happens across your full agent population.
- What Agent 365 Covers Now
- Unified inventory across Scout instances, Cowork task agents, Copilot Studio custom agents, and Microsoft’s pre-built D365 agents. Centralized permission visibility tied to each agent’s Entra identity. Activity monitoring through the Analytics Viewer role. Security posture surfacing – authentication gaps and policy impacts visible directly in the authoring experience for Copilot Studio agents.
- How It Connects to Purview
- Agent actions remain within the Microsoft 365 tenant boundary and are auditable through Microsoft Purview, the same compliance and DLP signal security teams already rely on for other Microsoft 365 surfaces. This means agent governance isn’t a parallel system to learn; it extends tools your security team likely already uses.

A Governance Checklist Given This Month’s Pace of Change
Given how much shipped this month alone, here’s a practical check-in worth running now, even if you ran a similar review when Agent 365 first reached GA: re-inventory your agent population — has anyone in your organization enrolled in Frontier or started piloting Cowork since your last review? Confirm spending limits are configured for any consumption-based agents (Cowork specifically) at the tenant, group, and user level. Verify that any newly built Copilot Studio agents — particularly any using the new computer-using agent or voice agent capabilities — have gone through your standard security role and least-privilege review. And confirm your Purview audit configuration is capturing activity from the newest agent surfaces, not just the ones that existed when you first set up monitoring.
For finance and operations leaders specifically: If your organization is piloting any of the D365-connected Cowork plugins, make sure that pilot is visible in your Agent 365 inventory from day one and not added after the fact. The habit of registering new AI capability in your governance system as you adopt it, rather than retrofitting governance later, is the single most important practice from this entire series.

📚 Go Deeper — Microsoft Resources
- Agent 365 — Original GA Announcement
- Copilot Control System — Security and Governance Framework
- Microsoft Scout — Identity and Governance Architecture Details
This month’s wave of new agent capability makes Agent 365 more important, not less – and the good news is that Microsoft built it to scale with exactly this kind of growth. The identity-per-agent architecture, the Purview integration, and the unified inventory across Scout, Cowork, and custom agents give IT and security teams a real path to governing this expanding surface area.
BB
Bobbi Bricker
ERP Capability Lead and D365 Functional Architect at Centric Consulting. Former controller. This series reflects fifteen + years in ERP (as an end user and a Consultant) and a genuine belief that AI, used thoughtfully, makes finance and operations teams more capable — not less. Reach out with questions, pushback, or war stories from your own organizations.
← Post 37: ERP Plugins for CoworkNext: The Licensing Shakeup →


Leave a Reply