Mojo UpDocs
Administration

Microsoft Agent 365

Give every enterprise team an Entra agent identity and a card in the Agent 365 registry, and see its runs and tool calls in Agent 365 observability.

An organisation with Microsoft Agent 365 governs its AI agents from the Microsoft 365 admin centre: one registry, Conditional Access and access reviews on each agent's identity, observability and Purview on what they did. Connect your self-hosted AIOE to it and the agents AIOE governs appear there too, beside everyone else's.

Self-hosted only

Agent 365 belongs to your own Microsoft tenant, the one your organisation signs in to AIOE with. Mojo Up AI Cloud organisations have no tenant of their own, so the panel is not offered there.

What you get

In Microsoft 365What AIOE does
An agent identity per agent member of each enterprise teamCreated from your agent identity blueprint when the team is saved, named <member> · <team> (AIOE), sponsored by the team's owner. The member card on every workbench shows "Entra agent · sponsor …", and the agent's audit rows and run records name the identity. A member taken off the team loses its identity; deleting the team deletes them all.
A card in the Agent 365 registryPosted for each identity with the member's name and team, its role and skills. Updated when the team changes.
ObservabilityEvery run a workbench or node reports (AI Workbench 0.51.0 and later) becomes one Agent 365 trace: the agent's turn, each model call, each tool call with what the policy decided, and the final message, sent with the member's own identity when the run ends. A project's policy can instead have machines send their own runs with a token the platform mints.
Registry ordersDisable, quarantine or enable a specialist on every machine from Settings; the order rides each machine's heartbeat until it reports it applied.
Microsoft SentinelConnect your data collection rule and every audit row worth a detection lands in your workspace with its place and hash in the audit chain.

Set it up

Create the blueprint

In the Microsoft Entra admin centre open Entra ID, Agents, Agent blueprints, and create a blueprint named for AIOE. The wizard sets its owner and sponsor and creates the blueprint principal.

Let it post cards

Give the blueprint's principal the application permission AgentRegistration.ReadWrite.All and grant admin consent. A blueprint creates agent identities from itself without a further role.

Give it a credential

On Azure, prefer a federated credential naming the deployment's managed identity: AIOE's panel shows the issuer, subject and audience to enter, and no secret is kept anywhere. Otherwise add a client secret (Agent ID Administrator role); AIOE keeps it sealed.

Connect

Open Settings, Microsoft Agent 365. Enter the blueprint's application (client) id, choose the credential, optionally the sponsor's object id, and Connect. AIOE gets a token with it first; a refusal keeps nothing.

Register the teams

Teams saved from now on get an identity and a card at once. For teams from before, Register every team, or Register on one. A step Entra or the registry refuses is shown on the team with the reason; Try again repeats only what is missing.

What is exported

Workbenches and nodes on AI Workbench 0.51.0 or later report every run as records. The platform builds one trace per run: an invoke_agent root with the prompt, model, tokens and outcome; a chat span per model call through the local proxy; an execute_tool span per tool call with the masked arguments and what the policy decided; and output_messages with the final message. What text rides along is the policy's Microsoft 365 section: nothing, text with secrets and personal data masked (the default), or text with only credentials masked. A run that met a data-protection block carries no text whatever the setting. A run nobody ended is closed as cancelled half an hour after its last record.

The export runs in the background and never holds up the machine that reported. The panel shows how many runs went, whether your tenant is licensed for Agent 365 observability, and the last problem, if any. Switch on Direct export in a project's policy and its machines send their own runs instead, with a short-lived token from the platform.

Stop a specialist everywhere

Under Stop or release a specialist everywhere, name the agent as team-id/Member name (the field offers the names), choose Disable, Quarantine or Enable, give a reason the person sees, and send. Disable stops the agent after its current turn; quarantine stops it at once, revokes its credentials and files an Inbox item on the machine; enable lets it run again. The order is repeated on every heartbeat until each machine reports it applied, and the panel shows how many have. A node's row on a workbench shows what it holds stopped.

Microsoft Sentinel

Deploy the shipped table, data collection rule and detections in your Sentinel workspace (from the AI Workbench repository's docs/integrations/microsoft-sentinel), give the Agent 365 blueprint's principal the Monitoring Metrics Publisher role on the rule, then under Settings, Microsoft Sentinel enter the logs ingestion endpoint and the rule's immutable id. From then on every audit row a machine reports with severity warn or high, and every data-protection decision, is a row of MojoUpSecurityEvents_CL with its AuditSeq and AuditHash. For a backfill, Audit, export, format Sentinel.

Disconnecting

Disconnect forgets the blueprint and its secret. Agent identities already created stay in Entra and are remembered, so connecting the same blueprint again picks them up. Remove on a team deletes its identity and card.

  • Tools: the policy that decides each tool call, and the Microsoft 365 (Work IQ) template.
  • Audit: every connect, registration, update and removal is an agent365.* entry.

On this page