---
title: Agents
description: Unified governance for every AI agent in your tenant - Copilot, Entra, and third-party - with the access insights and licensing you need to see them all.
icon: Bot
---

Microsoft spreads AI agents across separate admin portals - Copilot, Azure AI Foundry, and Entra - each with its own model, tags, and APIs. The **Agents** screen unifies all of them into one governed list, with the same access-insight lens 1Security applies to users, apps, and files.

## One screen for every agent

The Agents screen covers the three overlapping agent ecosystems Microsoft exposes:

- **Microsoft Copilot agents** - declarative agents built in Copilot Studio / Agent Builder (e.g. a SharePoint policy finder, a Teams message extension).
- **Entra Agent ID agents** - autonomous backend agents with their own Entra identity (Copilot Studio, Azure AI Foundry).
- **Third-party agents** - SaaS apps that use Copilot behind the scenes (e.g. Decisions, Adobe).

Instead of three consoles, you get one list - and, where the same agent shows up in more than one place, a **single unified record** that joins its Copilot chat presence to its Entra API permission grants.

## Unified access insights

Every agent is broken down by what it can actually reach - the same model 1Security applies to identities and apps:

- **Files, sites, users, and emails** the agent can access
- **Sensitive data** exposed through that access - down to the specific sensitive information types within reach
- **Activity** - what the agent actually did, drawn from the same audit-log pipeline as users and apps, with per-action breakdowns: created, modified, deleted, moved, shared, downloaded
- **Knowledge / data sources** it reads from - SharePoint, OneDrive, Teams, email, Graph connectors, Dataverse, the web - resolved to what's actually inside them, so you can review the content an agent learns from
- **Permissions** - every atomic permission with its source (direct, inherited from a blueprint, or declared) and Microsoft's "blocked for agents" flag

The value is the stitching: signals from **Copilot, Azure, and Entra** become one agent record, so you can govern an agent's behaviour and its real data access in one place - without hopping between portals.

## Working with Microsoft's agent stack, not against it

Everything above is read natively from Microsoft's own surfaces - Copilot, Entra, and Azure - so this inventory always agrees with the portals your admins already use. 1Security doesn't replace the agent platforms; it adds the governance layer they don't have:

- **Access, quantified.** Copilot Studio shows an agent's configuration; 1Security shows the blast radius - how many files, sites, users, and emails it can actually reach.
- **Sensitive data, before it leaks.** Access is one thing; what enterprises actually fear is an agent surfacing regulated data to whoever asks it a question. 1Security lists the exact sensitive information types within each agent's reach - payment cards, health records, credentials - so you know which agent could leak what, and can block that access before an employee's innocent prompt (or an injected one) turns reach into disclosure.
- **Activity, attributed.** Agent actions land in the same activity stream as users and apps, with per-action breakdowns - so "what has this agent deleted, moved, or downloaded?" is a filter, not a log-parsing project.
- **Knowledge sources, opened up.** In the agent platforms a knowledge source is a pointer; 1Security resolves it to the content behind it, so you can review what an agent would learn _before_ employees start chatting with it.

Licensing is the one place agents differ from the rest of 1Security: everywhere else Business Basic is enough, but Microsoft gates the Copilot agent catalog behind **Agent 365** - a single license on the admin account that connects 1Security unlocks it (details below). Entra-backend agents need nothing extra.

## Licensing: what you can see

Agent visibility depends on the tenant's Microsoft licensing. This is a Microsoft API limitation, not a 1Security one.

<Callout type="info">
  1Security **always** scans the Entra backend. A license only gates the
  Microsoft **Copilot Package catalog** - the API where lightweight Copilot
  agents live.
</Callout>

| Agent type                                                                                                                                                                                                                                                                                                                                    | Visible without Agent 365 | Needs Agent 365 |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-----------------------: | :-------------: |
| **Entra Agent ID agents** - everything Microsoft registers as an agent identity, including agents built in Azure AI Foundry and Copilot Studio, plus the earlier generation of both, which exist as ordinary service principals carrying Microsoft's agent tags (`AgenticInstance`, `AgentCreatedBy:CopilotStudio`, `power-virtual-agents-*`) |            ✅             |                 |
| **Declarative Copilot agents** - SharePoint policy finders, Teams extensions, and third-party wrappers like Decisions / Adobe (no Entra footprint; they live only in the Copilot Package catalog)                                                                                                                                             |                           |       ✅        |

Without the license, declarative Copilot agents either don't surface or look like ordinary enterprise apps - 1Security can't tell they're agents. This affects **both third-party wrappers and first-party declarative Copilot agents**, not just third-party apps.

## Licensing: what you need to buy

<Callout type="warn">
  You do **not** need the $99 Microsoft 365 E7 bundle. The product that unlocks
  the catalog is **Agent 365**.
</Callout>

- **E7 ("Frontier" suite)** just bundles E5 + Microsoft 365 Copilot + the Entra Suite + Agent 365. It's the expensive way in.
- **Agent 365** is available **standalone at ~$15/user per month** and can be added on top of an existing E3 or E5 - this is all the API actually checks for.

**You only need ONE license.** 1Security reads the catalog with a **delegated** admin token, so Microsoft validates the license of the single admin who connected it - not every user. License that one admin account and the entire tenant's Copilot agent catalog unlocks.

<Callout type="info">
  **For testing:** assign one standalone **$15 Agent 365** license to the admin
  account you use to connect 1Security.
</Callout>

## Connecting & graceful degradation

To scan Copilot agents, an admin connects a delegated token once (see the **Connecting Tenants** guide). Until that's done - or if the tenant has no Agent 365 - 1Security:

- still scans and governs every **Entra** agent,
- shows a banner on the Agents screen explaining that Copilot agents need Agent 365,
- never fails the tenant scan over a missing license.

### Talking to customers

A customer worried about Copilot security already owns Microsoft 365 Copilot - and Microsoft requires **Agent 365** to govern the agents they build with it using native tools, so most target customers already have it. If they don't, 1Security states the limit plainly:

> We can only scan your Entra backend. License your admin with Agent 365 to also scan your Copilot chat agents.
