Public preview: Manage agents across multiple tenants from the Microsoft 365 admin center
🚨 The Signal: New multi-tenant agent management in Microsoft 365 admin center allows consolidated viewing and control of AI agents across connected tenants. This centralises agent deployment, blocking, and permission review, impacting governance of autonomous identities.
The Impact
Security teams and administrators are affected by new capabilities to manage AI agents, posing a risk if not properly secured.
- Security Teams: Risk of uncontrolled agent deployment if GDAP is not tightly managed.
- Administrators: Risk of misconfiguring agent access across tenants, leading to unintended data exposure.
- Security Teams: Opportunity to enforce consistent agent policies and reduce shadow AI agent sprawl.
- Administrators: Opportunity to streamline agent lifecycle management and improve auditability.
The Action
- Review existing Granular Delegated Admin Privileges (GDAP) relationships to ensure least privilege for agent management.
- Define and implement a policy for agent deployment and blocking across all managed tenants.
- Regularly audit agent inventory and permissions in the Microsoft 365 admin center under 'All tenants > Agents'.
- For partners, ensure GDAP roles for agent management are scoped appropriately in Partner Center.
- For enterprises, configure GDAP relationships with strict role assignments for agent administration.
Domain: Agentic-AI · Impact: high · Workload: Other · Essential Eight: Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1507, ISM-1508, ISM-1509, ISM-1647, ISM-1648, ISM-1650, ISM-1686, ISM-1688, ISM-1689, ISM-1883, ISM-1897, ISM-1898