[AI] within REACH
Field Notes Vol. 02 · Agent Governance
Reading time · 7 min
Essay / N° 02

The Detection Gap in Agent 365 That Most IT Managers Miss

Agent 365 promises to detect shadow AI in your Microsoft tenant. It does, but only on Intune-enrolled Windows devices. This piece covers what it misses, what signal is already sitting in your Entra ID, and the 30-minute audit you can run this week.

Microsoft launched Agent 365 on May 1, 2026, positioning it as the answer to shadow AI inside Microsoft tenants. For any IT manager who has been watching employees adopt Claude, ChatGPT, and Gemini without oversight, the promise sounds like exactly what they need: a detection layer for AI tools running in their environment.

Agent 365 solves part of the shadow AI problem. The part it does not solve is the part where most of the risk actually lives.


[ 01 ]   What shippedWhat Agent 365 Actually Shipped

Microsoft launched Agent 365 at $15 per user per month as a standalone license. The positioning was clear: give IT teams visibility into AI agents running across their environment. For organizations already deep in the Microsoft ecosystem, this sounded like the missing piece; a detection layer for the AI tools employees had started adopting on their own.

Then came the licensing fine print. As of June 1, SMBs need Microsoft 365 Business Premium as a prerequisite, and enterprise customers need E5. SMBs on Business Premium can add Agent 365 at $15 per user per month, but they may also need Defender and Purview add-ons to access its full capabilities. That adds up fast. For a 50-person company already paying $22 per user for Business Premium, the additional $15 per user means $750 per month, or $9,000 per year, before those add-ons.

Agent 365's detection capabilities are real. Microsoft built something genuinely useful. Some SMBs on Business Premium will budget for it. But the second constraint matters more than the price.

The numbers behind the blind spot 2026 · cross-analyst
$15/mo
per user/month Agent 365 add-on for Business Premium.
Microsoft
29%
of employees use unsanctioned AI agents in their work.
Microsoft Cyber Pulse 2026
1545%
shadow AI growth on corporate devices in 12 months.
Verizon DBIR 2026
$9K
annual cost to add Agent 365 for a 50-person company.
Calculated · $15 × 50 × 12

[ 02 ]   The boundaryThe Detection Boundary Nobody Is Talking About

Agent 365 detects AI agents on Intune-enrolled Windows devices. That is its scope. Full stop on coverage. Microsoft's own documentation confirms that detection requires Intune enrollment and Defender for Endpoint. Browser-based AI usage; an employee accessing Claude through claude.ai, ChatGPT through chat.openai.com, or Gemini through gemini.google.com; falls outside that detection scope. So do BYOD devices that are not Intune-enrolled. So do Macs without Defender for Endpoint.

Consider what that means for a typical SMB tenant. Many mid-market environments include a mix of company-owned Windows devices, BYOD laptops, and Macs. If employees on non-Intune devices are using AI tools, and the Verizon DBIR data suggests nearly half of corporate device users are, Agent 365 has zero visibility into that usage.

Microsoft's own research confirms the magnitude. The Microsoft Cyber Pulse 2026 report found that 29% of employees use unsanctioned AI agents in their work. That number almost certainly undercounts reality, because it can only measure what Microsoft telemetry can see. Browser-based usage happening outside the Intune detection boundary is invisible to that measurement too.

The 2026 Verizon Data Breach Investigations Report tells the acceleration story. Shadow AI usage on corporate devices jumped from 15% to 45% in just twelve months; a threefold increase. The growth curve is not flattening. It is steepening. And the majority of that growth is happening in the exact channels Agent 365 cannot monitor.

When your detection tool covers Intune-enrolled Windows endpoints but your employees are running Claude in a Chrome tab on a personal MacBook, you have not solved your shadow AI problem. You have mapped one corner of the room while the rest stays dark.

This is not a criticism of Microsoft's product direction. Agent 365 addresses a real problem within its scope. The issue is the gap between what IT managers think they bought and what they actually got. When your detection tool covers Intune-enrolled Windows endpoints but your employees are running Claude in a Chrome tab on a personal MacBook, you have not solved your shadow AI problem. You have mapped one corner of the room while the rest stays dark.

[ 03 ]   The signalThe Signal That Is Already in Your Tenant

Before spending a dollar on new detection tooling, look at what Entra ID is already showing you. Most IT managers skip this step.

Every time an employee connects an AI tool to your Microsoft environment, granting it permission to read their email, access their calendar, pull files from SharePoint, that action creates an OAuth consent grant in Entra ID. It is a ledger of exactly which third-party applications have been given access to your tenant's data, who approved them, and what permissions they hold.

OAuth consent grants catch what Agent 365 misses. When an employee authorizes Claude to access Microsoft Graph from their browser, that does not register as an AI agent on an Intune-enrolled device. But it does create a consent record in Entra ID. The browser-based AI tools that are invisible to Agent 365's endpoint detection are visible in your consent logs, if you are looking.

Entra ID P2, which is included in Business Premium, can surface these grants. Configuring a consent review workflow is a step many organizations have not taken. The data is there. It is waiting to be used.

[ 04 ]   The roadmapWhat the Roadmap Promises vs. What You Need This Week

Microsoft's direction is right. The Agent 365 roadmap includes expansion to 18 agent types by mid-2026, including coverage for Claude Code. Entra ID Conditional Access policies for agent identities are in preview. So is a multi-cloud agent registry. If you are planning your 2027 security posture, these are worth tracking.

Preview features do not protect a tenant today. The employees at your company who opened a Claude account last month are not waiting for Microsoft's roadmap. They are pasting customer data into prompts right now.

In my book Generative AI Ready, I lay out the READY Framework: a five-phase sequence for AI readiness. The second phase is "Expose," which means mapping your actual data flows and access permissions through observation, not assumptions. You cannot secure what you have not documented. Agent 365 gives you one view. Your Entra ID consent logs give you another. Neither alone is complete.

[ 05 ]   The auditThe 30-Minute Audit You Can Run Today

Open your Entra ID portal. Navigate to Enterprise Applications, then filter by consent grants created in the last 90 days. Look specifically for applications with names that reference AI, chat, or assistant, and for any application requesting Mail.Read, Files.Read, or Calendars.Read permissions.

Cross-reference that list against your approved AI tool inventory. No approved inventory yet? That is your first finding.

The delta between those two lists is your shadow AI footprint. Agent 365 will not show it to you. Your Entra ID already does. Most tenants surface between three and eight unapproved AI integrations on the first pass, and each one represents a data-flow path that nobody authorized and nobody is monitoring.

If you want to do this across your full environment, endpoints, consent grants, browser-based tools, the whole picture, the [AI] within REACH AI Assessment is built for exactly that. It maps what your tenant controls, what it does not, and where your data exposure actually lives. It takes 20 minutes.

Get yours at our AI readiness assessment.

[ About Courser ]

Courser is a network of elite, locally operated MSPs — nationally supported — helping mid-market businesses adopt AI safely and get more from their technology, delivered across the US through locally branded and operated entities.

[ ]
[ Free AI Assessment ]

Agent 365 shows you one slice.
See the full picture.

It maps what your tenant controls, what it does not, and where your data exposure actually lives. Twenty minutes. Instant report.

[Get your free assessment] Book a 30-minute call Free · 20-min assessment or a call with our team