Microsoft 365 agent registry
289 agents in a 5,000-seat tenant. The registry lists every one.
Since 2026, the Microsoft 365 admin center carries an agent registry: Agents → All agents, one inventory across Microsoft, Agent Builder, Copilot Studio, Azure AI Foundry and the third-party agent store. In a 5,000-seat tenant we measured in September 2026, it held 289 entries - and 252 of them were store listings any user could install in one click. This page explains what the registry shows, what Agent 365 licensing adds on top, and how 1Security turns the list into decisions.
- Agents → All agents
- Agent Builder
- Copilot Studio
- Azure AI Foundry
- Third-party store
The registry
What "All agents" in the admin center actually shows
Open the Microsoft 365 admin center, then Agents → All agents. As of September 2026 that page is the closest thing to a complete agent inventory Microsoft ships: every agent from Microsoft itself, from Agent Builder, from Copilot Studio, from Azure AI Foundry, and every third-party listing from the agent store, in one table. It is part of the admin center you already run, on the licenses you already own.
The table does real governance work. It detects ownerless agents - entries whose maker has left or whose owner was never set. It carries a per-agent Block action. And its CSV export goes further than the screen does: alongside publisher and state, the export includes each agent's full instructions text and its capability flags, which is more than most admins expect to find in a spreadsheet download.
What the registry cannot tell you is which of those rows deserve your attention. A Microsoft-shipped agent your whole company uses and an unreviewed store listing with custom API actions sit in the same table with the same columns. The moment you have the list, every review meeting asks the next question: what can each of these actually reach, and what did it actually do.
Store shelf vs deployed
Most of the registry is a shelf, not a deployment
The numbers from a 5,000-seat tenant we measured in September 2026 - a mid-size tenant with no unusual AI program, counted straight from its registry export:
- 289agents in the registry in total
- 252third-party store listings marked "Available" - installable by any user in one click
- 128of those listings declare custom API actions
- 157ship their full instructions text in the CSV export
The distinction that matters is shelf versus deployed. "Available" does not mean someone chose the agent - it means the agent store put it on the shelf and nobody took it off. Until an admin blocks a listing, any user can add it to their Microsoft 365 in one click, and from that moment it works with whatever that user can reach.
The 128 listings declaring custom API actions are the part worth reading twice: a custom action is an outbound call to the vendor's own endpoint, which makes the agent a data path out of the tenant, not just a chat interface inside it. And the 157 instructions texts in the export are a free audit source - the agent's own system prompt, stating in plain language what it was built to do.
That is the third-party Copilot agents list nobody maintains by hand: the registry already holds it. The work left is reading it - and deciding, listing by listing, what stays on the shelf.
Blocking
Blocking agents in Microsoft 365 - and choosing which
The registry gives every entry a Block action. Blocked store listings disappear from what users can install; blocked tenant-built agents stop running for everyone. It is the one enforcement control that ships with the list itself, and it works per agent.
The hard part is not the button - it is the 252 decisions. Block everything and the shelf becomes a ticket queue; block nothing and every listing stays one click away from your data. A defensible middle needs evidence per listing: who has installed it, what it declared, what it can reach once installed, and whether its instructions text says anything its product page does not.
1Security is built for exactly that review: it imports the registry export, resolves each agent's reach into files, sites and mailboxes, attributes activity to the people who ran it, and flags instructions text that carries prompt-injection patterns - so the Block decision is a reading of evidence, not a guess.
Agent 365 licensing
What Agent 365 licensing includes - with the dates
Microsoft Agent 365 reached general availability in May 2026, priced at $15 per user per month and included in Microsoft 365 E7. It is the management add-on for the agent layer, and it gates a specific set of capabilities: the Graph Package Management API, the Risks column inside the All agents registry, the Security and Activity tabs on each agent, and Agent Map analytics.
Agent 365 also extends Microsoft's security stack to agents: Conditional Access and Identity Protection treat registered agents as identities, Purview applies data protection to them, and Defender covers them - the Defender cutover completed on July 1, 2026. For a tenant standardising on Microsoft's control plane, that is a coherent package with a clear price.
1Security complements that model rather than competing with it: it starts on the licenses you already own and grows with every license you add. The registry and its export are enough for a first full import; when Agent 365 joins your tenant, its signals join the same graph, with nothing to reconfigure.
- $15per user per month - Agent 365, GA May 2026
- E7Microsoft 365 E7 includes Agent 365
- Jul 1, 2026Defender coverage cutover for agents completed
What 1Security adds
From registry export to decisions, in four steps
1Security reads the same tenant the registry describes - starting on the licenses you already own, growing with every license you add. The registry export is the fastest way in.
- 01
Import the registry export
Upload the CSV from All agents and every entry lands on the 1Security graph, sorted into the Agents, Blueprints and Available tabs - deployed agents, the templates they came from, and the store shelf, each reviewed on its own terms.
- 02
Read permissions with their provenance
Every atomic permission with its source - direct, inherited or declared - including Microsoft's own blocked-for-agents flags, so you see which paths Microsoft already closed and which remain open. An agent access review takes minutes and survives an auditor.
- 03
Fuse reach with sensitivity
Not scope names: the exact files, sites and mailboxes each agent can touch, ranked by the sensitive data inside - payment cards, health records, credentials. "Available with custom API actions and reach into the finance site" is a different conversation than "252 listings".
- 04
Attribute activity and screen instructions
Every agent action is attributed to the person who drove it, measured against both baselines. Instructions text from the export is screened for prompt-injection patterns - the one review nobody does by hand across 157 system prompts.
Related
Where this fits
1Security + Microsoft Agent 365
How 1Security sits beside Microsoft's agent control plane - registry, identity and lifecycle on one side, measured reach and behaviour on the other.
See the pairing →AI agent inventory
The 1Security Agents screen in full: every ecosystem on one list, owners, blueprints, reach and last activity.
See the inventory →Copilot security
What Microsoft 365 Copilot itself can read in your tenant - the same oversharing problem, seen from the rollout side.
See Copilot →
FAQ
Questions admins ask about the agent registry
Where is the agent registry in the Microsoft 365 admin center?
In the admin center navigation under Agents → All agents. It lists agents from Microsoft, Agent Builder, Copilot Studio, Azure AI Foundry and the third-party agent store in one table, with ownerless-agent detection, a per-agent Block action and a CSV export. It is part of the admin center on the licenses you already own.
Do I need Agent 365 to see my agents?
The All agents registry ships with the admin center. Agent 365 - GA May 2026, $15 per user per month, included in Microsoft 365 E7 - adds the Risks column, the Security and Activity tabs, Agent Map analytics, the Graph Package Management API, and agent coverage in Conditional Access, Identity Protection, Purview and Defender. 1Security starts on the licenses you already own and grows with every license you add.
What does the registry CSV export contain?
More than the screen shows: name, source, publisher, owner and state, plus each agent's capability flags and its full instructions text. In the 5,000-seat tenant we measured, 157 of 289 entries shipped complete instructions text - effectively the agent's system prompt, in a spreadsheet. That export is exactly what 1Security imports.
Can users really install store agents themselves?
Yes - a third-party listing in the "Available" state can be added by any user in one click, unless an admin blocks it. In the tenant we measured, 252 of 289 registry entries were in that state, and 128 of them declared custom API actions - outbound calls to the vendor's own endpoints.
Does 1Security replace Agent 365?
No. Agent 365 is Microsoft's control plane for agents - registry, Entra identity, lifecycle, risk and security tabs. 1Security is the measurement layer beside it: reach resolved to actual files and sites, activity attributed to the people driving each agent, sensitivity fusion and prompt-injection screening. It starts on the licenses you already own, and when Agent 365 joins the tenant, its agents join the same graph.
Read your shelf before your users shop from it.
Export All agents from the admin center, import it into 1Security, and see every listing with its reach, its people and its instructions text - the same day.
Or leave the CSV in a folder until the next audit finds it.