The agentic tenant is already here

Your org chart just grew by a thousand. None of them are human.

Microsoft is rebuilding 365 around AI agents — and every agent is a new identity with its own permissions, its own reach into your data, and its own activity log. Built by employees in an afternoon. Shipped inside products you already licensed. Vetted by no one. 1Security is the one list they’re all on.

  • Copilot Studio
  • Azure AI Foundry
  • Entra Agent ID
  • Declarative Copilot agents
  • → one inventory

The quiet hiring spree

Three hires nobody interviewed.

Each one quietly acquires a slice of your tenant. Nothing in Microsoft’s admin surface puts the three of them on the same list.

  • The afternoon build

    An operations manager opens Copilot Studio after lunch and wires an agent to the finance site “to answer invoice questions”. By five o’clock it can read every document on the site. Nobody thinks of this as granting access — it felt like making a chatbot.

  • The overnight vendor

    A product you already license ships an update, and suddenly there’s a declarative Copilot agent in your tenant with a knowledge source nobody reviewed. It arrived inside the license, so procurement never saw it either.

  • The platform experiment

    A platform team spins up an agent in Azure AI Foundry to test a workflow. The test works, the agent stays, and its service principal keeps its permissions long after everyone forgot the experiment happened.

The inheritance

Agents inherit your mess.

98% of granted permissions are never needed. For years that was survivable, because the permission-holders were human — slow, distracted, unlikely to open ten thousand files on a Tuesday. The mess was real, but it moved at human speed.

An agent with those same permissions is your oversharing problem operating at machine speed. It will read everything it can reach, remember all of it, and repeat it to anyone who asks the right question. Copilot doesn’t leak — it surfaces what was always reachable. The rollout didn’t create the exposure; it made the exposure searchable.

  • 98%
    of granted permissions are never needed

One inventory

One inventory, atom by atom.

Discovery is the easy half. An inventory only earns its keep when it goes all the way down to the atoms.

  1. 01

    Every ecosystem, one list

    Copilot Studio, Azure AI Foundry, Entra Agent ID, declarative Copilot agents — every agent from every ecosystem in a single inventory, with its owner, its origin and its creation date.

  2. 02

    Blueprints reviewed once

    Fifty employees can clone the same agent blueprint. You review the blueprint once — its permissions, its knowledge sources — instead of chasing fifty copies through the tenant.

  3. 03

    Every permission, atomized

    Each permission with its source, its kind and Microsoft’s own blocked-for-agents flag — so you see at a glance which grants an agent holds that Microsoft itself says agents shouldn’t.

  4. 04

    Reach, quantified

    Not “it has Sites.Read.All” but the exact files, sites, users and mailboxes this agent can touch — resolved through the same permission graph that maps your humans.

Under watch

Watched like any employee.

Every agent gets an activity trail: what it read, when, how much. Every agent gets an anomaly baseline of its own — so “this one read 4× its usual files today” is an episode above your alert line, not a needle in a log.

And agents are policy targets like anyone else: alert when a new agent appears, when one gains a permission, when one touches a sensitive site. Agent risk lives in the same machinery as human risk — not in a separate console you’ll check less often.

The reveal

And everyone else too.

Here’s the widening shot: the graph that inventories your agents is the same graph that maps your humans, your devices, your OAuth apps and your data. AI is the newest identity type on it — not a separate product.

Because the access problem was always bigger than the robots. Agents didn’t create it; they gave it urgency. The tool that counts your agents also answers who-can-reach-what for everything else in the tenant.

Before the rollout

Guardrails before rollout.

The right order is boring: clean up what’s reachable before Copilot ships, then prove the boundaries after. 1Security does both — it finds the oversharing agents will amplify, retires it, and once the agents arrive, watches each one against its own baseline.

Connect read-only today, and the first scan returns the number your rollout plan is missing: how many agents you already have.

Count your agents.

Most organizations are off by an order of magnitude. Connect read-only and get the real number today.