Microsoft Defender introduced AI agent posture risk assessment in public preview in July 2026, and the capability arrives at exactly the moment enterprise AI agent deployment is accelerating past the point most security teams can track manually. Microsoft Defender assesses posture risk for AI agents in an organisation, including agents registered with Microsoft Agent 365 and local agents discovered on endpoint devices, evaluating each one against risk indicators and assigning an overall risk level based on the likelihood of compromise and the potential impact if compromised.
What Actually Gets Assessed
The risk indicators behind each agent’s score are specific and behavioural rather than purely configuration-based. An indicator might flag that an agent is published and accessible beyond a pilot group, that it can run without human approval, that it holds privileged access to sensitive systems, or that it already carries active security alerts. For local agents discovered running on individual endpoint devices, Defender additionally weighs device and user context, since a local agent often inherits the permissions of whatever user account it runs under, which means an agent running under a highly privileged user’s identity carries meaningfully more risk than the same agent running under a standard account.
This matters because it moves AI agent governance away from a one-time approval decision made when an agent is first built, toward continuous monitoring of how that agent’s actual behaviour and access evolve after deployment. An agent approved with modest permissions six months ago that has since been granted broader access, or connected to additional data sources, shows up in this framework as a genuinely higher risk agent today, independent of whether anyone formally re-reviewed it.
The Agent 365 Licensing Connection
The capability’s dependency on Microsoft Agent 365 is the detail with the most direct commercial relevance for anyone managing Microsoft licensing. When an Agent 365 licence is enabled, Microsoft Defender integrates with Agent 365 to secure all managed agents, including local AI agents on supported endpoints, with threat detection built on observability data from Microsoft Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot Agent Builder, and agents integrated through the Agent 365 SDK.
That dependency means the full posture risk assessment capability is not simply a feature that ships automatically with an existing Defender subscription. It requires Agent 365 licensing to unlock the complete picture, which is a meaningful new line item for organisations that have not yet evaluated Agent 365 specifically, and a strong argument for organisations already running Defender and Copilot Studio to fold Agent 365 into that conversation rather than treating it as a separate future decision.
What Counts as a Local Agent and Why That Category Matters Most
The local agent category deserves particular attention because it captures exactly the kind of AI activity most likely to exist entirely outside formal governance today. Unlike agents built deliberately through Copilot Studio or Microsoft Foundry, which at least pass through a development process someone consciously initiated, local agents discovered running on endpoint devices frequently originate from an individual employee installing or configuring an AI tool without any IT involvement at all.
That distinction is precisely why Defender’s ability to discover these agents automatically, rather than relying on a voluntary registration process, matters so much more than it might first appear. A governance framework that only covers formally registered agents misses the exact population of agents most likely to carry the highest actual risk, since nobody deliberately reviewed their permissions or data access before they started running.
Why the Governance Gap Is Wider Than Most Teams Realise
Independent technical analysis from Microsoft’s own MVP community has been direct about how fragmented AI agent governance responsibility currently is across a typical enterprise. IT teams work in the Microsoft 365 admin centre and need visibility into agent inventory and lifecycle management, developers work in Microsoft Foundry and need security signals embedded directly into their build and operate workflows, and security teams work across Defender, Purview, and Entra and need unified threat detection and compliance reporting, with each team operating in a genuinely different control plane while needing access to the same underlying shared security primitives.
That fragmentation is precisely why a centralised posture score, visible consistently regardless of which team or tool built a given agent, has genuine value beyond its technical function. It gives security leadership a single number to escalate on, rather than requiring someone to manually reconcile agent inventories across Copilot Studio, Foundry, and endpoint-discovered local agents that were never formally registered anywhere at all.
The Cultural Shift This Capability Reflects
Microsoft’s own framing of this shift has been notably blunt about the stakes involved, and worth quoting for how directly it captures the risk. One Microsoft engineering lead described agents as the most powerful productivity tool given to users since the spreadsheet, but pointed out that spreadsheets never had the ability to email an entire client list or delete Azure resources on their own initiative, concluding that governance is not optional, it is the price of admission for deploying agents at scale.
That framing is a useful internal talking point for any organisation trying to justify Agent 365 investment to budget holders who see it as an optional add-on rather than a genuine control requirement. The comparison to spreadsheets lands because it names precisely why agent governance cannot simply borrow the lighter-touch approval processes organisations historically applied to other productivity tools.
Why This Preview Matters More Than a Typical Feature Rollout
Public preview features from Microsoft frequently sit in that state for months without materially changing an organisation’s near-term planning. This one is different because the underlying problem it addresses, ungoverned agent sprawl, does not wait for a feature to leave preview before it accumulates. Every week an organisation delays establishing basic agent visibility is a week in which employees and developers continue building and connecting agents without any centralised record of what exists, what data it touches, or what actions it can take autonomously.
Treating this specifically as a preview worth adopting early, rather than waiting for general availability, reflects the asymmetry between the cost of turning on a visibility feature now versus the cost of discovering, months from now, that dozens of ungoverned agents have been quietly operating with access nobody formally reviewed.
Building a Practical First Response
For organisations with any meaningful AI agent activity already underway, whether built deliberately through Copilot Studio or accumulated informally as employees experiment with local agent tools, the practical starting point is simply establishing visibility before attempting full governance. Turning on Defender’s AI agent inventory, even before deciding whether to invest in the full Agent 365 licence, gives a first honest picture of how many agents actually exist in a tenant, which is frequently a larger and more surprising number than IT leadership expects.
From that baseline, prioritising posture review for agents flagged with the highest combination of privileged access and unapproved autonomous action, rather than attempting to review every discovered agent with equal urgency, makes the initial governance effort tractable rather than overwhelming for a security team already stretched across existing priorities.
Conclusion
Microsoft Defender’s new AI agent posture risk assessment closes a genuine and growing visibility gap, but its full capability is tied directly to Agent 365 licensing, making this as much a commercial decision as a technical one. Organisations already running Copilot Studio or Foundry-built agents at any scale should treat Agent 365 evaluation as a near-term priority rather than a future consideration, given how quickly agent sprawl accumulates once employees and developers start building without centralised oversight.
Establishing basic agent inventory visibility now, even ahead of a full Agent 365 licensing decision, and building the cross-functional governance process that spans IT, development, and security teams are the two most useful immediate steps, since the posture scoring capability itself is only as valuable as the organisational process built to act on what it reveals.