Token Observe vs Microsoft Agent 365
Agent 365 governs the agent as an identity in your tenant. Token Observe governs the payload that agent sends to a model provider.
2 September 2026
- Microsoft Agent 365 — product and pricing page
- Microsoft Learn — Microsoft Agent 365 overview
- Microsoft Learn — Agent 365 service description
- Microsoft Learn — Agent overview in the Microsoft 365 admin center
- Microsoft Learn — Microsoft Purview for Microsoft Agent 365
- Microsoft Learn — enable security for AI agents using Microsoft Defender
- Microsoft 365 blog — Agent 365: the control plane for AI agents
- Microsoft Security blog — Agent 365 general availability
- Microsoft Learn — Secure Web and AI Gateway for Copilot Studio agents
- Microsoft Learn — AI Gateway prompt injection protection in Global Secure Access
Their claims, not our testing. Verify anything that decides it for you.
On this page
For an organisation already on Microsoft 365, Agent 365 is the better purchase, and it is not close
The decisive advantage is that Agent 365 governs agents with the same machinery that already governs your people, and that machinery is enormous. Microsoft’s service description lists Entra access packages defining the scope of agent permissions, built-in Entra lifecycle policies driving sponsor workflows, Conditional Access and identity protection extended to agents that hold delegated access, Purview audit logs and eDiscovery content search of agent interactions for legal and investigative hold, Purview data lifecycle management over agent-generated data, Insider Risk Management extended to agents, sensitivity labels that agents inherit and honour, DLP that blocks agents from accessing and sharing sensitive content, Defender detection of misconfigurations and exposure risks with relationship mapping from agents to devices and MCP servers, and Intune device compliance for agent Conditional Access. Their admin-centre documentation adds registry inventory across Copilot Studio, SharePoint, Agent Builder, Foundry, the Agents Toolkit and non-Microsoft platforms such as Manus or Genspark, and conditions-based lifecycle rules; the service description adds tenant-wide control of which tools including Microsoft MCP servers agents may reach, a Graph API over the registry and its governance actions, and monitoring and blocking of malicious and noncompliant network traffic for agents operating on user devices and for Copilot Studio agents. Token Observe has an agent registry, a policy engine, approvals, budgets, a flight recorder and an audit chain. It has none of the rest, and its own roadmap names a replacement enterprise identity provider and a broad CMDB-style AI inventory competing with Microsoft as strategic non-goals, so it is not going to grow them.
The second advantage is assurance and commercial standing, and it is the one that ends most procurement conversations before the technical ones start. Agent 365 reached general availability for the commercial segment on 1 May 2026 on Microsoft’s own overview page, it is a Microsoft 365 service running in your existing Entra tenant, and its certifications, regional commitments, service levels and data-processing terms come from the Trust Center and the Product Terms that your legal team has almost certainly already signed. Ask Microsoft directly for the scope and date of each; this page does not hold them for you. Token Observe holds no certification of any kind — no SOC 2, no ISO 27001, no ISO 42001, no independent penetration test — offers no availability SLA, publishes no price list, and its licence is a template pending review by counsel rather than an executed grant. If your gate is an attestation or a signed uptime commitment, the comparison is over on that row alone.
The third is direction of travel, and Token Observe’s own market analysis records it as pressure on itself rather than as an opening. The hyperscalers are bundling generic gateway, registry and policy features, and the ground left to a separate product narrows every quarter. Microsoft’s GA post already describes registry sync from AWS Bedrock and Google Cloud in public preview, partner agents deployable directly from the admin centre, Defender asset-context mapping across the devices an agent runs on, the MCP servers configured for it and the identities associated with it, runtime blocking of coding agents, and Entra network controls extended to Copilot Studio agents and to agents running on user endpoint devices — restricting connections to approved web destinations and helping block malicious prompt-based attacks. That last one reaches the same traffic the rest of this page argues about, which is the honest reason to read the remaining difference as narrow rather than structural. Expect next year’s Agent 365 to cover more than this year’s. Every description of Agent 365 on this page is drawn from Microsoft’s public, vendor-authored material and has not been independently tested; verify preview status, regional availability and exact policy semantics with Microsoft during procurement rather than from a comparison page.
Token Observe and Microsoft Agent 365, capability by capability
The Microsoft Agent 365 column paraphrases Microsoft’s own published material as it stood on 2 September 2026. None of it has been independently tested here, products in this category ship quickly, and a capability that is absent from a vendor’s documentation is not the same thing as a capability the product lacks. Check anything that decides it for you against their own current documentation.
Where it sits
A tenant control plane. Their admin-centre documentation calls the Agent workload the grounding control plane for all agents managed at your organisation, with the registry in the Microsoft 365 admin centre, Microsoft Entra and Microsoft Purview. Where their documentation describes interception, it names a specific surface: Copilot Studio runtime, Microsoft 365 channels, the device, the network.
A gateway the traffic passes through. Eleven ordered steps in one process — authenticate, resolve agent, open trace, sanitise, scan, govern, enact, route, call upstream, govern the proposed tool call, meter and record.
Both are inline somewhere. The question for a buyer is which object each one is holding when it decides, because that fixes what a rule can be written about.
Through identity and registration. Their product page describes agents published through Microsoft 365 channels receiving an Entra Agent ID and entering the inventory automatically; their admin-centre documentation describes an agent extended with the Agent 365 SDK becoming an agent instance with Entra-backed identity, extended observability, covered MCP tooling and an IT-approved template system, and describes registry sync scanning connected external platforms.
By changing one environment variable. For supported OpenAI-compatible, Anthropic and Gemini ingress a base-URL change plus one key is normally the whole integration, and an agent record with four required fields — name, owner email, team, declared purpose — is the row the gateway resolves at step 2.
Their service description states Agent 365 works with agents built on Microsoft platforms and with agents built or acquired from third-party sources, and the GA post names AWS Bedrock and Google Cloud registry sync in public preview. On the model call itself, the GA post states that Agent 365 extends Microsoft Entra network controls to Copilot Studio agents and to agents running on user endpoint devices, and that those controls can restrict connections to only approved web destinations and help block malicious prompt-based attacks before they lead to harmful actions. Their Global Secure Access page describes AI Gateway prompt injection protection inspecting AI traffic inline and blocking adversarial prompts before they reach AI models, preconfigured for ChatGPT, Claude, Cohere, Deepseek, Gemini, Grok, Meta AI, Mistral, Perplexity, Pi and Qwen, with a custom URL and JSON path for anything else.
OpenAI, Anthropic, Google Gemini, OpenRouter, Amazon Bedrock and Azure OpenAI as first-class upstreams, plus any OpenAI-compatible endpoint you register, with identical policy, redaction, budgets and tracing enforced by a table-driven test over every provider kind.
Microsoft reaches this traffic, and their own pages publish the conditions alongside the capability: a Microsoft Entra Internet Access licence, TLS inspection and the Global Secure Access client on Entra-joined or hybrid-joined Windows devices, or a Copilot Studio environment with traffic forwarding switched on in the Power Platform Admin Center. The published action on that route is block, on text prompts up to 64,000 characters. A verdict that removes one detected value and lets the same call continue, and a per-agent USD ceiling reserved before egress, are not described in the Agent 365 material cited here as of 2026-09-02.
Their service description lists control over which tools, including Microsoft MCP servers, agents can access tenant-wide, at the Microsoft 365 E7 and Agent 365 tiers. Their Defender onboarding page describes real-time protection scanning agent tool invocations for Copilot Studio agents, once a Power Platform administrator completes the integration.
One Streamable HTTP endpoint in front of every registered upstream MCP server, tools namespaced and filtered to the agent’s grants, every call re-authorised at execution, and each descriptor hashed at approval so an upstream rewrite quarantines the tool until a human approves it again.
Their Purview documentation states that supported audited interactions include all agent-to-human, human-to-agent, agent-to-tools and agent-to-agent interactions.
The delegation chain intersects permissions at every hop rather than unioning them, so a low-privileged agent gains nothing by routing a refused action through a higher-privileged one.
These are not the same claim. Theirs is about what is recorded; the Token Observe row is about what is refused. Ask Microsoft what is enforced on an agent-to-agent hop, separately from what is logged.
Their blog describes quarantining unsanctioned agents so they cannot be discovered by users; the service description lists Defender syncing shadow AI endpoint agents and Intune blocking unsanctioned local endpoint agents, and the GA post describes using Intune policies to detect and block the common methods of running OpenClaw on managed Windows devices, surfaced through the Shadow AI page in the Microsoft 365 admin centre.
A radar with five evidence sources — vendor bill reconciliation, network egress analysis, a service-account key audit, IDE and CLI telemetry, and Token Observe’s own tables. Four of the five run on exports you send; a default install has no access to your billing, network or IAM systems at all.
Microsoft’s route runs through managed devices and its own tenant signals. Token Observe’s runs through exports you choose to supply, and reports its own coverage state beside every clean result.
What it enforces
Their blog describes agent policy templates and adaptive, risk-based access policies enforced through Microsoft Entra under the principle of least privilege; the service description lists policy templates, conditions-based lifecycle rules, Entra access packages defining the scope of agent permissions, and Conditional Access extended to agents holding delegated access.
A trigger, an action and a scope, evaluated on every governed request. Seven trigger kinds — tool and argument values, model and estimated size, spend, rate, detected data classes, injection score and source, hour of day — resolved to one verdict in which a block beats an approval and an approval beats a redaction.
Their Purview documentation describes sensitive information types and trainable classifiers finding sensitive data in user prompts and responses, and DLP supported by naming agent instances in a policy as you would a user, with supported interactions given as block or audit for agent-to-human and human-to-agent in Microsoft Teams, OneDrive or SharePoint, and email. The same page describes Endpoint DLP on Windows computers onboarded to Purview warning or blocking users who share sensitive information with third-party generative AI sites accessed through a browser, giving a credit card number pasted into ChatGPT as its example. A verdict that removes a detected value from the request and lets that same request continue to the provider, rather than blocking or auditing the interaction, is not described in their published documentation as of 2026-09-02.
The payload itself, before egress: Unicode sanitisation first so smuggled invisible characters are stripped before any detector reads the string, then eleven sensitive-data classes of which three are checksum-validated, then a redaction plan applied to the outbound body — and on streamed responses, a hold-back buffer so a card number split across two chunks cannot escape masking.
Their Purview documentation is explicit about the DLP case: because an agent instance is unaware of the block action, the agent owner must actively monitor a DLP policy that uses this configuration and understand the impact to subsequent workflows.
A typed refusal the agent receives synchronously. The trace closes as blocked, the caller gets ACP_POLICY_BLOCKED, and on a stream the block ends the response with an in-band frame the instant the class is seen, because the status line is already spent on the first byte.
This row is the clearest published difference between the two products and it is worth reading as a design choice rather than a defect: a control at the Microsoft 365 boundary stops the data leaving; a control in the request path also tells the caller why.
Their Defender onboarding page describes real-time protection scanning agent tool invocations, detecting suspicious behaviour or cross-prompt injection attacks and blocking malicious actions for Copilot Studio agents, with an alert raised in the Defender queues. Their Purview documentation describes an Insider Risk Management risky AI usage template detecting prompt injection attacks and access to protected materials.
Nine weighted heuristics over prompts and over tool results, with tool results scored 1.25× higher because that is the channel through which agents are actually hijacked. It is pattern matching rather than a model, and the published limit says so.
Their admin-centre documentation describes reviewing and approving pending agent requests to allow or restrict deployment, with approval of agent requests and ownership assignment restricted to the AI Administrator or Global Administrator roles.
An approval bound to the SHA-256 of one canonicalised action plus its execution context, single-use through a compare-and-set, expiring at 60 minutes by default and one minute to seven days by policy. Change one argument and the retry is refused as a mismatch.
Different granularity for different questions. Theirs approves an agent into service; Token Observe’s parks one refund on one named person. An estate can want both, and neither substitutes for the other.
Their admin-centre documentation publishes agent run-time as a metric — total hours worked by agents in the last 30 days, from when a user request begins to when it completes — alongside active users over the same window. A per-agent monetary ceiling or token rate limit enforced before a provider call is not described in the Agent 365 material cited here as of 2026-09-02.
Hard USD ceilings per request, per rolling hour, per UTC day and per UTC month, plus requests, tool calls and tokens per minute, reserved against the agent’s windows in one per-agent transaction before egress. A budgeted route whose reachable target has no price is refused with a 409 rather than priced at zero.
Microsoft meters and bills AI consumption in several places across its estate, and this row is narrower than that: it is about a ceiling enforced on the Agent 365 governance path before a provider call is made. Ask Microsoft what exists, on which surface, and whether it stops a call or reports on one.
Their service description lists basic governance actions including block and delete; the GA post describes Defender being able to block coding agents in runtime when a managed agent exhibits malicious behaviour patterns, such as attempting to access or exfiltrate sensitive data, and Intune blocking the common methods of running local agents on managed devices.
A kill switch scoped to one agent, one team or the whole estate, checked first in the pipeline — before the lifecycle check, before permissions, before budgets — so it reaches even the routes that execute nothing.
What it records
In your Microsoft 365 tenant. Their Purview documentation states that prompts and responses are captured in the unified audit log like other activities, flowing into activity explorer and the DSPM AI observability page, and that an agent instance created for Agent 365 is automatically enabled for audit and for detection of sensitive data with data classification.
In your own database, in a flight recorder holding the post-redaction prompt excerpt, the tool calls and arguments, the policy decisions, the approvals, the tokens and the cost, with each step explained in a plain sentence.
Their Purview documentation describes searching the audit log for Agent 365 activities and using activity explorer in DSPM; their Defender page describes investigation and advanced hunting over AI agent activity once the Microsoft 365 connector is enabled.
A plain-English question translated into a validated filter object over fourteen allow-listed fields — never into SQL, because trace content is attacker-influenced by construction — shown back as editable chips, and degrading to a deterministic keyword parser when no model is configured. It cannot group, count or correlate across traces.
Their Purview documentation describes audit solutions for searching and managing audit records and for responding to security events, forensic investigations, internal investigations and compliance obligations, with prompts and responses captured in the unified audit log like other activities. The construction that makes those records resistant to tampering, and the retention tier it applies to, is not described in the Agent 365 material cited here as of 2026-09-02 — Microsoft documents audit retention and immutability across its wider Purview set, so treat this as a question to put to them rather than as a gap.
A hash chain in which each entry’s digest covers the previous hash plus that entry’s canonical content, so a break is reported at a named sequence number. Unkeyed SHA-256 by default, which an operator with write access can rewrite and recompute; HMAC-SHA256 with an off-box MAC key; Ed25519 anchoring of the head to an off-box sink with a signing key. Every verification result names which of the three you hold.
Tamper-evident, not tamper-proof. The only claim an anchor buys is that any copy kept off-box beats any rewrite made after you took it.
Their Purview documentation describes retention policies automatically retaining or deleting prompts and responses for AI apps, with conflicts resolved by the principles of retention so the longest applicable duration wins, and eDiscovery cases searching agent interactions stored in a user’s mailbox, holding them and exporting them to a review set.
Default trace retention is keep-forever, which is a storage-growth decision you make deliberately rather than a tier you buy. There is no legal-hold workflow and no review set.
Their Purview documentation describes exporting eDiscovery results directly from a review set, and their service description lists export and hold for legal, regulatory and investigative needs.
A compliance export bundling traces and events for the period, approvals with approver identity and rationale, audit entries covering every governance-plane change, and a chain verification result naming the sequence number of any break — sealed with a SHA-256 digest at a recorded time. The bundle is not itself signed.
Their admin-centre documentation publishes agent run-time in hours, active users over 30 days, trending agents by active users and a breakdown by creation platform, with the caveat that metrics derive from several underlying systems and minor variances from ingestion timing are expected.
USD per governed request, per provider, from usage normalised into mutually exclusive token buckets before any arithmetic — because Anthropic reports cache reads and writes outside the input total while OpenAI and Gemini report them inside it — and the route narrowed after the call to whichever provider actually served it.
Two different currencies of the same question. Hours of agent run-time answer a value question for a business sponsor; USD per provider answers a reconciliation question against six invoices.
How it deploys
A Microsoft 365 service in your Entra tenant. Their overview describes management through the Agent 365 registry in the Microsoft 365 admin centre, Microsoft Entra and Microsoft Purview, and their Defender page describes security for AI agents being enabled automatically on onboarding to Agent 365.
Self-hosted only. One Node process and one SQLite file, with PostgreSQL behind the store ports as an evaluation alternative rather than a supported high-availability topology. No managed option exists.
Their overview states that Agent 365 works best with Microsoft E5 as a prerequisite and that at least one user must hold a qualifying licence to enable it. Their Defender page adds a Security Administrator role or higher, the Microsoft 365 connector for investigation and hunting, collaboration with a Power Platform administrator for Copilot Studio real-time protection, and Defender for Endpoint in active mode for local agents onboarded separately from cloud agents.
Node 24, an offline demo with a built-in mock provider that needs no API keys, then your own provider keys. The onboarding document times the first hour honestly: install, setup, first governed trace.
A Microsoft-operated cloud service processing agent interactions in your tenant. What is processed and retained, and under which regional commitments, is a question for Microsoft’s Product Terms and Trust Center rather than for this page.
Nothing. No product telemetry, no phone-home, no prompts, no keys, no trace database. Governed payloads leave your network only for the model and tool providers you configure, after policy and redaction, and the runtime data flow is documented so you can verify it.
Their service description lists Intune device compliance for agent Conditional Access, a policy-controlled environment for agent runtime and blocking of unsanctioned local endpoint agents; the GA post describes detecting managed devices and blocking common methods of running a local agent.
A preview surface that decides inside each vendor’s own administrator hook for Claude Code, Codex and Copilot, locally against an Ed25519-signed policy bundle with no network call, delivered through a managed-settings channel the developer cannot remove. It is not claimed to be equivalent to an inline gateway on an unmanaged device.
Microsoft’s route requires the device to be managed by Intune. Token Observe’s requires the vendor’s hook to exist and the settings channel to be in place. Neither covers a laptop outside both.
Their service description points to the Product Terms site for licensing terms and the Microsoft Trust Center for security and accessibility. Ask Microsoft which certifications and regional attestations cover Agent 365 specifically, for what scope and to what date.
None held: no SOC 2, no ISO 27001, no ISO 42001, no independent penetration test. What exists instead is a published residual-risk register, a published defect list naming the attacks that still work, and a licence drafted to permit a pre-purchase test with no gag clause and no pre-approval of results.
What it costs
Per user. Their product page prices Agent 365 at $15 per user per month on an annual commitment and its FAQ recommends a licence for all users who interact with, own, manage or sponsor Agent 365-managed agents; their overview repeats that it is licensed on a per-user basis and that general availability began on 1 May 2026 for the commercial segment.
No published price list. The commercial arrangement is discussed rather than looked up, which is a real disadvantage in a procurement process that starts with a budget line.
Their service description states Agent 365 is available as a standalone subscription for use with eligible Microsoft 365 subscriptions and is also included with Microsoft 365 E7; their product page prices E7 at $99 per user per month on an annual commitment, beside Agent 365 standalone at $15. Their Global Secure Access page adds that Agent 365 is also available as an add-on to Microsoft E5, A5 or Business Premium.
Nothing to bundle with. Token Observe is one component and does not arrive inside a suite you already own.
Their service description splits the feature list explicitly. Registry inventory, basic governance actions, conditions-based lifecycle rules and registry sync from external platforms are listed as available on Microsoft 365 Enterprise, Business, Education and frontline plans. Policy templates, observability and telemetry, tenant-wide tool control, the Graph API, Entra access packages and Conditional Access, and every Purview, Defender and Intune row are listed for Microsoft 365 E7 and Agent 365 only.
One product with modules that default off — audit anchoring, policy backtesting, on-behalf-of intersection and radar scheduling each require an operator to switch them on, so an upgrade changes no behaviour until somebody decides.
Worth reading the service description’s table row by row before assuming a capability is in the plan you hold. Several of the rows a buyer would consider central sit above the base plans.
Their service description directs licensing terms and conditions for volume-licensed products to the Product Terms site.
Commercial source-available: use, modify and self-host under a licence, with redistribution and offering it as a competing hosted service excluded, and security research and publication of results expressly permitted. The licence file is a template pending review by counsel rather than an executed grant.
Governing the agent and governing the call are different jobs, and the boundary is published
Agent 365’s unit of governance is the agent as an object in your tenant. It has an Entra Agent ID, an owner, a sponsor, a lifecycle, a set of access packages describing what it may reach, a Conditional Access posture inherited from the person it acts for, and a risk state aggregated across Entra, Defender and Purview. Every control Microsoft publishes hangs off that object: approve it into service, restrict which users and groups may use it, control which tools and MCP servers it may reach tenant-wide, expire or flag it by rule, quarantine it if it was never sanctioned. That is a coherent and well-founded model, and for an agent whose entire working life is inside Microsoft 365 it is close to complete.
Token Observe’s unit of governance is one request. The payload is in front of it, which is what makes a different class of rule expressible: block when a card number appears in this prompt, redact this class of data out of this response, park this exact refund on a named approver, refuse because this agent has spent its monthly ceiling, stop because the estimated input size crosses a threshold on this model. None of those are statements about an agent; they are statements about a call the agent is making right now, and they resolve at step 6 of eleven, before the payload leaves your network.
The boundary between the two is visible in Microsoft’s own wording rather than inferred, and it is narrower than a comparison page would like it to be. Purview DLP for agents is documented as blocking or auditing agent-to-human and human-to-agent interactions in Teams, OneDrive or SharePoint and email — Microsoft-owned surfaces, which is precisely why the control is well attested there. Defender’s real-time protection is documented as scanning agent tool invocations for Copilot Studio agents after a Power Platform administrator completes the integration, and their documentation notes that if the Microsoft 365 connector is not connected, real-time protection continues to block suspicious activity during runtime but the alerts do not appear in the Defender portal. And Microsoft does reach the model call itself: the general-availability post extends Entra network controls to Copilot Studio agents and to agents running on user endpoint devices, and the Global Secure Access page describes AI Gateway prompt injection protection inspecting AI traffic inline and blocking adversarial prompts before they reach ChatGPT, Claude, Gemini and eight other named models. So the question is not whether Microsoft is on that wire. It is what each control is holding when it gets there, and under which conditions it is there at all: a network proxy that sees the traffic of an Entra-joined Windows device running the Global Secure Access client, or of a Copilot Studio environment with forwarding enabled, and whose published action on it is block — against an in-process gateway that holds the parsed request for whatever caller you point at it, and can also remove one field and let the call continue, reserve a USD ceiling against it, and park it on a named approver.
- Their decision point
- The agent’s identity and its access to tenant resources, plus named runtime surfaces: Copilot Studio tool invocations, Microsoft 365 channels for DLP, the managed device for Intune, and the Global Secure Access proxy for agent traffic that has been forwarded to it.
- Token Observe’s decision point
- Step 6 of eleven, before egress, returning one verdict — allow, block or require approval — plus a redaction plan, and step 10 again on any tool call the model proposes on the way back.
- The overlap to sort out first
- Both hold a registry with an owner and a lifecycle. Decide which one is authoritative before you run both, because two systems of record with different opinions about who owns an agent is worse than either alone.
One policy set and one chain across six providers, and exactly what that is worth
The claim Token Observe makes that a single-tenant control tower structurally cannot is cross-provider equivalence. One agent can be routed across OpenAI, Anthropic, Google Gemini, OpenRouter, Amazon Bedrock and Azure OpenAI, and the same permissions, policies, redaction, budgets and tracing apply whichever serves the request. That equivalence is enforced by a table-driven test over every provider kind rather than asserted in a document, and the stated reason for the expense is the sentence worth carrying into any evaluation of a multi-provider control: a policy that fires on OpenAI but not on Gemini is worse than no policy, because it produces a governance report describing coverage you do not have.
Routing carries the same discipline into failover. A route rule names a primary and an ordered fallback chain; every candidate is filtered through the agent’s three data-policy flags — zero retention, no training, serving region — before it can be used, so failing over cannot route around a constraint. Failover is typed rather than counted: a timeout, a 429 or a 5xx moves on, while a content-policy refusal, an authentication failure, an over-long context and a malformed request all stop where they are, because otherwise the chain quietly launders a refusal into a success and the report says the request succeeded.
The limits belong in the same paragraph. Nothing in Token Observe verifies a provider’s own data-policy claim; those flags are unverified operator assertions with a named risk acceptor. The strongest available is the Bedrock region binding, which ties a declared policy region to a region proven by an AWS-owned runtime endpoint and fails closed on a contradiction — configuration consistency, not data residency, and not your network path. And the whole thing is only worth its cost if you genuinely run more than one provider. If every model call in your estate goes to Azure OpenAI, cross-provider equivalence is a feature you are paying for and not using, and the Microsoft answer is better.
What Token Observe deliberately will not rebuild, and why that shapes the pairing
Two of Token Observe’s seven strategic non-goals point directly at this page: do not build a replacement enterprise identity provider or credential vault, and do not build a broad CMDB-style AI inventory competing with Microsoft or ServiceNow. The instruction attached to them is to implement adapters and evidence exchange for those layers instead. That is not modesty; it is the recorded consequence of reading Microsoft’s own material and concluding that first-class agent identity, sponsorship, lifecycle review and Conditional Access are table stakes owned by the directory rather than territory worth contesting.
So Token Observe’s identity surface is deliberately small, and its limits are published rather than implied. Console sign-in federates an OIDC provider and maps directory groups to roles, with bounded SCIM user provisioning alongside it that accepts lifecycle for viewer accounts, permits disable but not rename or reactivation once an account holds more authority, and revokes sessions on disable — while omitting hard delete, groups, bulk operations, passwords and extension schemas. Group claims are a snapshot with a default staleness of 24 hours rather than a live directory read, so a revoked group keeps granting until the next sign-in or that expiry, and that residual risk requires written acceptance. Agent credentials are long-lived hashed bearer tokens because the agent frameworks the product must support today cannot present a workload identity in the SPIFFE sense; revocation, expiry and last-used recording compensate.
The registry follows the same rule. It is a system of record for governed agents rather than an estate-wide inventory, and it does not discover anything for you: registering an agent is a deliberate act by a named person, and anything calling a model without a record is the radar’s problem rather than the registry’s. Where an authoritative upstream inventory already exists — and Agent 365 with Entra Agent ID is exactly that — the intended shape is to attach authority and effect evidence to those assets rather than to hold a competing list. Nobody should read this page as an argument for two registries.
- What recertification adds beside a lifecycle review
- A named reviewer attests a SHA-256 digest of the exact configuration in front of them, and the digest covers each referenced role’s normalised permissions rather than merely its id — so editing a role makes every affected review stale immediately, without rewriting what was actually attested. What it will not do is act: an overdue agent keeps serving until a person suspends it.
- What the on-behalf-of mask does
- Off by default. When enabled, the directory groups mapped from the named human principal intersect the agent’s authority after the verdict and before the approval branch, so the mask can only narrow and a human is never asked to approve something the intersection forbids.
- What is not on offer at all
- No eDiscovery case management, no legal hold, no sensitivity labels, no device compliance, no Conditional Access, no Graph API over your tenant. If those are the requirement, this is the wrong product and Agent 365 is the right one.
Where each one is the right answer
Choose Microsoft Agent 365 when
- Your agents live inside Microsoft 365 — Copilot Studio, SharePoint, Agent Builder, Foundry, the Agents Toolkit — and the governance you need is identity, sponsorship, lifecycle and access to tenant resources.
- Compliance obligations run through eDiscovery, legal hold, retention policy and Compliance Manager assessments, all of which Microsoft publishes for Agent 365 and Token Observe does not have in any form.
- Procurement needs a published price, an existing master agreement, certifications with a scope and a date, and a service commitment somebody signs. Token Observe offers none of those.
- Local agents on managed devices are the exposure, and Intune device compliance plus Defender for Endpoint runtime protection is a route you already operate.
- Network-layer control of agent traffic is the requirement and the route is already yours: Entra Internet Access licensed, TLS inspection configured and the Global Secure Access client deployed, with AI Gateway prompt injection protection blocking adversarial prompts before they reach eleven preconfigured models.
Choose Token Observe when
- You run more than one model provider — or one cloud plus one frontier lab — and the same rule now has to bind identically on all of them, with the equivalence tested rather than asserted.
- A hard USD ceiling has to stop a call before egress rather than appear on an invoice, per request, per hour, per day and per month, with an unpriced route refused rather than counted as free.
- An approval has to be spendable exactly once against exactly one payload, so a retry with one argument changed is refused as a mismatch rather than allowed as near enough.
- Self-hosting in your own network with nothing returning to a vendor is a requirement — including air-gapped operation, which the licence is drafted to permit, though it remains a template pending counsel.
When you would run both
Running both is the normal answer, and Token Observe’s own roadmap is written to make it the expected one: a replacement enterprise identity provider and a broad CMDB-style AI inventory competing with Microsoft are named strategic non-goals, and the instruction is to federate the authoritative systems and attach action evidence rather than recreate them. In that arrangement Agent 365 stays authoritative for what it is authoritative for — the Entra Agent ID, the sponsor and owner, the lifecycle rules, the access packages, Conditional Access for agents acting with delegated authority, Purview classification, retention, eDiscovery and audit across Microsoft 365 surfaces, Defender posture and hunting, Intune device compliance — and it remains the inventory of record for the tenant. Token Observe takes a narrower job on traffic Microsoft also reaches, and the division is what each one holds rather than who gets there first: the outbound model and MCP payload, parsed inside the caller’s own process path rather than at a forwarded network proxy, so it can be redacted field by field rather than only blocked, held against a hard USD ceiling before egress, bound to a payload-specific approval, and recorded in one hash chain covering OpenAI, Anthropic, Gemini, OpenRouter, Bedrock and Azure OpenAI rather than one cloud. The honest caveat is that this is a division of labour rather than a shipped integration: there is no Agent 365 connector in Token Observe today and this page does not claim one, so anyone running both is operating two policy sets and must decide which system owns which rule — starting with which of the two registries is authoritative for who owns an agent.
The category argument sits above this one: Token Observe and cloud-native controls covers what the whole category does and does not do, which is the better page to read if you have not yet shortlisted a product.
The others in the same slot
Amazon Bedrock AgentCore
AgentCore enforces Cedar at its own gateway boundary. Token Observe enforces one rule set across six providers from a process you run. The estate decides which you want.
Microsoft Entra Agent ID
Entra decides which identity the agent holds and whether it may be issued a token. Token Observe decides the individual call that token does not cover.
ServiceNow AI Control Tower
AI Control Tower governs an AI asset through a lifecycle. Token Observe governs one request before it leaves your network.
Is Token Observe an alternative to Microsoft Agent 365?
Not for most of what Agent 365 does. Microsoft publishes Agent 365 as a control plane to observe, govern and secure agents, built on Entra Agent ID, the Microsoft 365 admin centre registry, Purview and Defender, with Intune and Conditional Access alongside. Token Observe has no directory identity, no eDiscovery, no sensitivity labels, no device compliance and no Graph API, and its roadmap names a replacement identity provider and a Microsoft-competing inventory as strategic non-goals. Where the two genuinely meet is inline refusal, and even there they hold different objects: Agent 365’s documented blocks act on Microsoft 365 channels, Copilot Studio tool invocations, the device and the network, while Token Observe holds the outbound model or MCP payload. If governing agents inside Microsoft 365 is the requirement, Agent 365 is the product built for it.
We already pay for Microsoft 365 E7. What would Token Observe add?
A narrower thing than it first sounds, because E7 already reaches the model call: Entra network controls extended to Copilot Studio agents and endpoint agents can restrict connections to approved destinations and block malicious prompt-based attacks. What Token Observe adds on top of that is a different set of verdicts on the same traffic, applied identically across OpenAI, Anthropic, Gemini, OpenRouter, Bedrock and Azure OpenAI, with the equivalence enforced by a table-driven test over every provider kind, and applied wherever the caller runs rather than only where a Global Secure Access client or a forwarding-enabled Copilot Studio environment is. That buys a hard USD ceiling reserved before egress rather than an hours-worked metric after the fact, a redaction plan applied to the outbound body and to streamed responses through a hold-back buffer, an approval bound to the SHA-256 of one exact action, and a single hash-chained record spanning every provider that you can key and anchor off the box. If every model call in your estate goes to Azure OpenAI and every agent lives in Microsoft 365, the honest answer is that E7 already covers you and adding a second fail-closed component in the request path buys a second failure domain for portability you are not using.
Does Agent 365 block a prompt before it reaches a model provider?
On a published route, yes, and the scope of that route is the thing to check rather than the fact of it. Microsoft’s general-availability post states that Agent 365 extends Microsoft Entra network controls to Copilot Studio agents and to agents running on user endpoint devices, and that those controls can restrict connections to only approved web destinations and help block malicious prompt-based attacks before they lead to harmful actions. Their Global Secure Access page is more specific: AI Gateway prompt injection protection inspects AI traffic inline at the network layer and blocks adversarial prompts before they reach AI models, preconfigured for ChatGPT, Claude, Cohere, Deepseek, Gemini, Grok, Meta AI, Mistral, Perplexity, Pi and Qwen, with a custom URL and JSON path for anything else. The prerequisites are published beside it — a Microsoft Entra Internet Access licence, TLS inspection, and the Global Secure Access client on Entra-joined or hybrid-joined Windows devices — and for Copilot Studio the equivalent is traffic forwarding switched on per environment in the Power Platform Admin Center. Separately, Purview DLP blocks or audits agent-to-human and human-to-agent interactions in Teams, OneDrive or SharePoint and email, and Endpoint DLP warns or blocks a user pasting sensitive data into a third-party generative AI site in a browser. What differs is not who reaches the wire first. It is what can be done once there: their published action on that route is block, on text prompts up to 64,000 characters, for devices and environments inside those conditions; Token Observe holds the parsed request in the caller’s own process path, so it can also remove one field and let the call continue, refuse because a USD ceiling is spent, and require an approval bound to the hash of that exact payload.
Both products keep an audit trail. What is the difference?
Scope and construction. Microsoft’s Purview documentation states that prompts and responses are captured in the unified audit log, that an agent instance is automatically enabled for audit on creation, and that supported audited interactions include agent-to-human, human-to-agent, agent-to-tools and agent-to-agent — with eDiscovery, retention policy and legal hold sitting on top, none of which Token Observe has. What is not described in the Agent 365 material cited here is the integrity construction behind those records — Microsoft documents audit retention and immutability across its wider Purview set, so ask them for the specifics rather than reading a gap into it. Token Observe publishes its construction in three layers and names the weakest first: unkeyed SHA-256 by default, which an operator with write access can rewrite and recompute, and the repository ships a forgery test asserting exactly that; HMAC-SHA256 when an off-box MAC key is configured; Ed25519 anchoring of the head to an off-box sink when a signing key is set. Every verification result and every export names which of the three you hold. It is tamper-evident rather than tamper-proof, and compliance exports are sealed with a SHA-256 digest rather than signed.
How much does each cost?
Microsoft publishes theirs and Token Observe does not, which is a genuine disadvantage rather than a rhetorical one. Their product page prices Agent 365 at $15 per user per month standalone on an annual commitment, or bundled in Microsoft 365 E7 at $99 per user per month, licensed per user for those who interact with, own, manage or sponsor Agent 365-managed agents; their overview adds that Agent 365 works best with Microsoft E5 as a prerequisite and that at least one qualifying licence is needed to enable it. Read their service description’s feature table before assuming a capability is in the plan you hold: registry inventory, basic governance actions, conditions-based lifecycle rules and registry sync are listed for the base Microsoft 365 plans, while policy templates, observability and telemetry, tenant-wide tool control, the Graph API and every Entra, Purview, Defender and Intune row are listed for E7 and Agent 365 only. Token Observe publishes no price list, and its licence is commercial source-available under a template pending review by counsel.
Have you tested Agent 365 against Token Observe?
No. Every claim about Agent 365 on this page paraphrases Microsoft’s own published pages read on 2 September 2026 — the product and pricing page, the Learn overview, the service description, the admin-centre agent overview, the Purview and Defender integration pages, the two Global Secure Access pages covering agent traffic and AI Gateway prompt injection protection, the November 2025 Microsoft 365 blog post and the May 2026 general-availability post — and none of it has been independently tested. There has been no witnessed bake-off. Where a cell says a capability is not described on the pages cited here, read that as an instruction to ask Microsoft rather than as a finding: a capability that is merely undocumented reads identically to one that does not exist, Microsoft documents across many product sets, and Agent 365 changed materially between its announcement and its general availability. Ask in writing, and ask for the scope and the date.
Prefer to ask a person? Write to us →
Tell us which one you are already running.
If Microsoft Agent 365 is already in your stack, the useful question is not which to buy but what each is for, and where the seam between them sits. Say what you have and you will get a straight answer — including when the answer is that you do not need a second thing.
no form · no qualification step · no sales desk · the other three ways in