Microsoft Foundry adds governance and security controls for enterprise AI agents
In brief
- Azure AI Foundry now supports publishing agents to Microsoft 365 Copilot and Teams with full governance controls.
- Agent-to-Agent functionality allows individual agents to coordinate within larger enterprise workflows.
- Every agent receives its own identity through Microsoft Entra ID and automatic Agent 365 registration for compliance visibility.
Publishing and Coordination
Azure AI Foundry now supports publishing agents directly to Microsoft 365 Copilot and Teams, marking the headline addition to the platform. The capability arrives with general availability status, meaning it's production-ready for enterprise deployment. Alongside this, Autopilot agents and Agent-to-Agent functionality are landing in public preview. The Agent-to-Agent feature matters because real enterprise processes rarely fit inside a single task—individual agents can now coordinate with each other inside a larger workflow, handling sequential and parallel work that would otherwise require manual orchestration.
Identity, Governance, and Compliance
Every agent created on Foundry receives its own identity through Microsoft Entra ID, Microsoft's identity and access management service. Agents are automatically registered in Microsoft Agent 365 following credentialing, providing IT and compliance teams centralized visibility. This matters for regulated industries. Agent publishing requires identity verification, admin approvals, and organizational visibility checks before availability in Microsoft 365 Copilot, creating a governed pipeline that prevents unauthorized deployment.
Model deployment policies are scheduled for general availability by August 2026. These policies restrict which models can be deployed based on pre-approved criteria, giving enterprises a compliance lever they can control. A new Foundry Control Plane is also on the roadmap, designed to provide fleet-wide oversight across all deployed agents. Azure Policy enforcement and content safety filters round out the compliance toolkit, giving administrators controls over agent actions and content processing.
Resilience and Isolation
For long-running agents, Microsoft is adding resilience capabilities. By September 2026, long-running hosted agents will gain resilience capabilities in preview. Durable identities and lease-based recovery ensure an agent working through a multi-hour process doesn't simply disappear if something fails mid-task. The platform also supports per-session isolation with persistent file systems for hosted agents. Each agent session gets its own sandboxed environment with scale-to-zero economics, meaning agents consume no resources when idle. Microsoft is also adding managed access toolboxes and durable state storage for long-running agents, two features that address the operational complexity of agents running unsupervised in production environments.
"For heavily regulated industries like finance, healthcare, and legal services, that's not a nice-to-have. It's a prerequisite for deployment at all."
Foundry's architecture places security, auditability, and policy enforcement into the workflow from the moment an agent is created. This isn't an afterthought bolted onto a platform designed for speed. It's foundational. That distinction matters for organizations that can't deploy tools without passing security audits, compliance reviews, and regulatory sign-off. Microsoft's move signals that enterprise AI adoption won't happen at the pace of consumer AI—it'll happen at the pace of governance and risk management.


