Microsoft Teams Insider

Understanding Agent 365 Hands On: Managing and Securing AI Agents with Microsoft's Graham Hosking

Tom Arbuthnot

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 43:53

Graham Hosking, Senior AI Solutions Engineer at Microsoft, breaks down Agent 365, Microsoft's approach to observing, governing, and securing AI agents across multi-platform environments.

• How Agent 365 builds on existing Entra, Defender, and Purview capabilities to provide full visibility over AI agents

• Live demo of a fully autonomous LangChain agent automatically flagged for risky behaviour by Defender

• How third-party agents from Amazon, Google, Databricks, and Salesforce can be brought into a central registry

• The Agent 365 SDK and how partners like Adobe, Atlassian, and Lovable are already baking in observability

• Shadow IT monitoring for local AI agents via Defender for Endpoint

• MCP tools and plugin management for controlling end-user access

• Licensing breakdown: end-user based, one seat lights everything up, and the E5 to E7 step-up path

• Bonus demo of Morgan, a fully autonomous digital CFO with voice and avatar interaction built on LangChain

Thanks to Crestron, this episode's sponsor, for their continued support of Empowering.Cloud

Graham Hosking: Morgan is actually built on LangChain, sat in Azure, connected to the Microsoft IQ APIs using a Microsoft partner for the avatar. So the world's your oyster these days. You can build and combine everything you want. The world is now a big Meccano set

Tom Arbuthnot: Welcome back to the show. This week, Graham takes us through Agent 365. This is a very demo-heavy session. He decodes all the marketing, helps explain what it is, how it works, how it works with Microsoft first-party agents, agents you build yourself, but also critically third-party agents from ISVs and agents you build on other platforms as well. Many thanks to Graham for decoding it all and showing us the demos, and even giving us a sneak peek at a new voice base agent he built at the end. And many thanks to Crestron, who are the sponsor of this show. Really appreciate all their support to the community. On with the show. Hey, everybody. Really excited for this session. Agent 365 is absolutely a hot topic at the moment, or the hotter topic is trying to manage and control and understand all these agents in our organizations. And the reality is most organizations are doing something with agents and don't have complete visibility. But Graham is gonna decode that problem and what Agent 365 does for us. Graham, I think everybody in the community knows you by now. We've done quite a lot recently as well. But for those who don't, can you just do a quick, roll and intro?

Graham Hosking: Yeah, of course. Lovely to be back as well, Tom. I'm Graham Hosking. I'm one of the Solution Engineers here in Microsoft. I look after all of our wonderful Software Developers in Europe. So very busy. Like Agent 365 is a hot topic because they're also building agents internally and externally for their customers as well. So yeah, I've been dragged over the coals on this one it feels. But yeah- Yeah... lovely to talk about it more.

Tom Arbuthnot: And, and, and that's interesting, isn't it, in the ISV landscape because this can cover third-party agents in certain scenarios, as well as first party, as well as built in-house.

Graham Hosking: Everything, yeah. And, and that's, like you

Tom Arbuthnot: Said- Everything's a big promise, Graham... kind of decoding that. Everything's a big promise.

Graham Hosking: Everything is a big promise. And we'll go through some of the nuances, I think, because like there's, there's two sides of this when, when I'm talking to, to customers who are interested in kind of observability and understanding a little bit more about what kind of agents that they have, but they think when they're going to Microsoft for a tool that is only in the Microsoft ecosystem, which is obviously not true. It's never been true. And having that flexibility to create agents wherever you want, but then being able to hook in Agent 365 to look inside of that black box is what it's all about.

Tom Arbuthnot: Yeah, I love that phrase hooking in. You're gonna talk about that more. Yeah. But like it's a, like a... The early marketing, I felt like it was like, "Don't worry, magic will happen." Yeah. A- and like we've got much more detail on how, Agent 365 can get visibility of third-party agents.

Graham Hosking: Yeah, and, and they think, most people think that, yeah, one, it is magic. It's not magic by, by any means, but it is stuff that people have been using for the last sort of decade or so. I remember when, like, Microsoft released E5, I, I was there in the very early days when I started at Microsoft, and this, kind of suite of different products, and of course, that also entailed things like security and compliance, of which I specialized in for many, many years- Yeah with kind of Microsoft Purview. But all of that stuff that we're used to in kind of managing users that we have today, we do exactly the same thing and use exactly the same technology, but with a lens on agents this time.

Tom Arbuthnot: And, and that's Microsoft's kind of high level thinking is like we've had Entra and Defender and Purview for years and years and years in the people space, and you can take a similar paradigm to we want to watch what agents are doing.

Graham Hosking: Yeah. That's exactly it. So this is the life's most common slide I show. I, I swore to you, Tom, that I wouldn't show any slides. I'll just- Yeah, we're

Tom Arbuthnot: Going demo heavy today. But this is... I'll give you this one.

Graham Hosking: Thank you so much. Yeah, so I normally talk about, like- everything that you do for users today, if we think about, like, the front door to any organization, like we all work at home these days or pro-predominantly do anyway, or trying to stay at home I think, is when you're logging on to, to your corporate laptop in the morning, like, there's gonna be some sort of identification about you and the systems you're trying to access, right? So we think about access packages, we think about conditional access, we think about, like, having an identity not just for me, but also an identity for these types of agents as well, so they're in a registry. And all of those same capabilities that we do for human beings today, we're also doing for agents. So say, for example, that I want to, interact with an agent, but I'm in a different country, and that's unsanctioned. Guess what? Like, we can have conditional access policies that restrict you to access not just that agent, but maybe can accia- access the agent in part, but not the data that you're not allowed to access from that specific country, if that makes sense. So there's a lot of flexibility that you can create in those, those policies. But also, the whole part of the Microsoft ecosystem, including Agent 365, is you can create those templates and those blueprints. So any agent that's being created in your organization has to fit inside of those policies too. So you're not building something that's gonna do something really bad. You've already got that grounding of that compliance built into it. So you're empowering your end users to use the tools to build agents to help them, but also the guardrails to support that. Does that make sense?

Tom Arbuthnot: It does, and I, I think it's interesting, like, LLMs and, and AI is non-non-deterministic, so it has the chance that it will do different things at different times. Again, just like people. Like, like, "Here's your job. Here's what we're broadly expecting you to do. Like, but we need some kind of, you know, we're not gonna give you access to everything that you don't need access to, because why would we? That's just not best practice." Exactly. So I think particularly with AI, it's like that, that kind of govern and observability, like we set the system up with this in mind, but actually th- it, it may do different things. We need to watch it. But also, as I think the LLMs change, we've seen, like y- when you swap in and out a particular model, I know you've done some of this, Graham. Like the models act differently. So actually, if I wanna move- They do... from 5 to 5.5 for my custom-built agent, it will behave differently, and you're gonna wanna know what's happening.

Graham Hosking: Yeah. And that's, again, part of the point is non-deterministic actions. You might create an agent in, say, Copilot Studio, where you can use the new evaluation capabilities, right? So you can look at the history of what conversations users have had with agents so far, and then you can reuse those questions to figure out whether the agent is giving the right answer or not, responding with the, with the right information. But as you said, you know, these models are changing every couple of weeks, or in, in Fable's case, like being released and then revoked- No, not released and then re-released... and then released again. Yeah. But yeah, that, that changes the, the behavior of these types of agents. And, I make a joke as well wh- when I'm kind of bu- helping customers or my customers build agents, like, I feel more like an English teacher because they'll, like, build instructions for an agent and, they'll be like, "Well, it doesn't do the thing that I want it to do," and I'm like, "Well, did you tell it?" Yeah.

Video: And they're

Graham Hosking: Like, "Oh, no, I didn't tell it to do that thing." But then when they change it and they have told it, they're like, "It still doesn't do it." I'm like, "Well, how did you instruct it to do the thing? Is there a different way that you could phrase that language in order to make it do the thing- Yeah that you want it to do?" So you're right, you know, non-deterministic tools with generative AI is there, but also that kind of brain, just like we do as human beings, right? We have this brain of things that we want to do, like moving arms and legs. But the other analogy I use as well is, like, driving. Like, you don't just jump in a car and drive. Like, someone's gotta teach you, right? You need to have those instructions. But you need to have deterministic, capabilities to drive a car as well, like a steering wheel, an engine, and wheels. But also you need to have all of those sensors within the car to ensure that, one, you know, the, the car is operating as it should, right? We have that built in. It's analogy to Agent 365 again, by the way. Bear with me on this one. But also, like, we have, if you've got a more modern car- I won't name brands on here, but you have, sensors that's monitoring the human being as well, right? So you're monitoring whether they're awake, you know, do they need a caffeine, shot or something? Do they need some sleep? Are they kind of going in a different lane? So you've got those other types of sensors as well, and kind of bringing it back into to Agent 365 again, rather than go into cars, is utilizing some of the tools that you've already got access to. If I share my screen, is we can go into things like Defender, and there's new capabilities in here as part of the Agent 365 to do the monitoring. So I built a fully autonomous, AI teammate, as we call them, or digital workers or digital coworkers, whatever you wanna call, call them these days. And, I built this using-

Tom Arbuthnot: And what is that, Graham? Help, help people, like, 'cause agents means everything and nothing really at the moment. Like, what- It does in this context, what, what a- what platform was that agent built on, or how was that built?

Graham Hosking: Yeah, good question. So there's two types of agents you can build today. One we've had for quite a while, which is on behalf of agents. So if you're using things like Copilot or you've built an agent in Foundry, for example, you as a human being are interacting with that agent, but it has, the same permissions as you do, right? So it's working on behalf of you. This fully autonomous agent has its own identity, so an Entra, it's got its own ID- Mm-hmm... that it logs on with. It's got its own agent ID, its own registry So all of that governance, templates I talked about earlier on, but it's also got its own mailbox, its own access to systems, its own access to data, its own memory, right? So-

Tom Arbuthnot: It... And is, is this a parallel to what we're seeing with Autopilots and Scout? So Scout initially, 'cause it seems to be taking your user token and acting pretty much as you, but we saw Satya- Yeah... in the keynote say s- Autopilots will have Entra identities, mailboxes, like, they will be an entity in their own right.

Graham Hosking: Yeah. So that's still, like, with Scout, like, the, the Scout that we have today in Frontier that runs on behalf of you. Yes. Yeah. So it's running on your local machine, access to the same systems as you do, has access to your mailbox through, like, WorkIQ. So that's still running on your behalf. I'm talking about kind of the next stage. Like, there's very few of these I see in the enterprises yet. But you can build agents that are working autonomously like you do as a coworker, right? So Tom- Yeah... you're gonna g- go away and do your work after this session today, right? I don't know what you're going to do, but you've got a job role, and you've got tasks that you need to do. So these fully autonomous AI teammates also have a specific job role, a description, a persona. It could be a marketing person, right, looking for the next podcasts that you're going to do-... and figure out what's, happening out in the field. So you can have these AI agents that actually, reach out to you in reverse. So just like you would reach out to me, Tom, hopefully for the next podcast, like, you

Tom Arbuthnot: Have these-

Graham Hosking: We'll see how this one goes... well, I know. You can have, you can have these agents, like, reach out to you and call you over Teams. Yeah

Tom Arbuthnot: So this.

Graham Hosking: This- And.

Tom Arbuthnot: And if you're following this space industry-wise, this is the thing, this is OpenClaw, this is Hermes. Like, this is... I- in those cases, people are typically using things like, they're using Telegram or WhatsApp or whatever. But there's definitely- Interact with them... been a really positive hook of there's something about psychologically, rather than being, like, prompt response or I- the agent can automate my emails into I've given this agent a, like you say, job to do. It's marketing research. It, it is proactively going out there, keeping an eye on what's going on on the internet and bringing me back ideas. Yeah. And I'm really excited about this in things like Teams, where it's like people can somehow mentally grip a Teams identity, an Entra account with a mailbox, with a Teams account that I can talk to and come back to and I can bring into Teams scenarios. So I'm, I'm- Yeah... really excited about this, not just technically, but about how in terms of adoption it's easier to understand that virtual agent Jack is our, you know, Marketing Analyst that's proactively doing things for us.

Graham Hosking: Yeah And that's exactly what it is. Yeah, you could have those agents spun up, and then if you wanted to bring them on a call or even onto this podcast, wouldn't that be a cool thing for the future? Is that can sit there, and we can interact with it via, different modalities as well. So, that could be via voice, it could be via video. If we get a chance, I'll try and, show you Morgan as well, which is, a fully autonomous agent that we can interact with. Yeah, yeah. Let's have a look. Yeah. But there's- Sorry, take

Tom Arbuthnot: It all back. So, we've, we've defined the agents. Yeah. So, we've got, like, these agents have Entra accounts. They're, they're entities, and- Yep... and you're seeing Defender now look at one of your agent doing things, is that right?

Graham Hosking: Yeah, exactly. So, what, when I typically show the Agent 365 interface, the reaction I get from my customers, 'cause it's predominantly IT that we would talk about kinda Agent 365 and the security of these agents, they, they s- then say, "Well, is that it? Is that just the user interface that we're paying for?" And we're like, "No." Like, you've got Entra, you've got agent policies in there. You've got Defender, which I'll show you in a second, that we have agent policies in here that we're monitoring for potential risks. And then we're also using, Microsoft Purview then from a security or data security point of view and highlighting risks of data there. So, it's all of that kind of grounding, all surfacing back up into Agent 365. And the reason why I started with, Cassidy, which is, designed to be an operations manager, again, fully autonomous, so they're running around on their own actually doing work, is we want to observe those types of agents, right? And, I built Cassidy quite a while ago, and then I noticed these risks being surfaced up, in my tenant. And then, in Agent 365, you can click on those agents that are, are showing those types of risks, and it takes you off, over into the relevant areas within kinda Defender Purview and, Entra. And this was just one that w- it was showing there was a tool being used, and there was, some anomalies that was coming up. So let me just see if I can show you this live for a second. This was anomaly for t- for a tool by one of your AI applications. We're at a low risk, right? Mm-hmm. So we're having all of that, machine learning kinda built into these applications. And what I saw down here is Defender was saying, like, a threat actor was trying to use prompt manipulation techniques to invoke one of the available tools in the AI app that had a harmful impact. I'm like, " okay. This is interesting because I know-" You got my

Tom Arbuthnot: Attention.

Graham Hosking: Yeah, how this agent was built. Like, it's can send emails. It can also call people on Teams. It's also got PSTN connections as well, so it can make outbound calls. That's cool, right? But the cool thing was in here, it says that either a threata- threat actor or a third-party tool that was connected to the agent was using an indirect prompt injection by triggering harmful actions that was running on behalf of the user permissions. Like, without that Agent 365 piece and then Defender assessing that risk over a period of time, I wouldn't have known, right? So- Yeah... this is where, like, you're gonna benefit from Agent 365 and doing that end-to-end monitoring like you do for your users, but now we're kind of leading into the future with these as fully autonomous agents. I think you, you have to have some sorta tools that's monitoring for all those interactions because there's going to be thousands, if not millions, of different agents. How are you gonna do that? So that was just a really cool, kind of thing that happened to me as I was building these agents, and I obviously showcased Agent 365. I'm like, "Look, there's a real one here for an incident that was in my tenant." So Cassidy's- And so

Tom Arbuthnot: What was happening-... cool... what was happening in that scenario, Graham?

Graham Hosking: Yeah. So what was happening is it had access to a number of different tools, and there's, a recursive loop that it goes round in its job description to do tasks. So as part of those, tools, they also interact with other AI agents as well, and it was just sending a prompt to another agent, and the agent was kind of responding to that and then triggering, actions to connect to the tools that it had. So it's kind of a, a looping method between multiple agents, but it was just a... It wasn't anything harmful, of course. That's where we can see the risk is low.

Tom Arbuthnot: Yeah.

Graham Hosking: But it's still enough to trigger an incident, though I could see many alerts- Yeah... as part of that.

Tom Arbuthnot: And that agent to agent you touched on is really interesting, isn't it? Because... like, you'd be like, "Well, the agent's internally facing, and we're using it within the marketing team, and I trust my people in marketing, so maybe we're cool." But we're, we're certainly getting closer and closer, if not people are doing it already, where the- Yeah... marketing agent works with a researcher agent, and the researcher agent works with the video specialist agent. And now- Yes... you've got no people working out what they're doing between each other. So this visibility suddenly becomes really interesting.

Graham Hosking: It does, yeah. It's quite cool 'cause the Cassidy and Morgan, if we get time to show you, is, their agents are actually built on LangChain. So those types of agents can sit anywhere, so they could sit in Google, they could sit in Amazon, for example. These ones are actually sat in Azure, but just to kind of show you that you can build third-party agents in any platform. So it's being, surfaced up as potential risk because inside of that LangChain agent, I've infused it with the Agent 365

Tom Arbuthnot: SDKs and there's a s- That's what I was gonna ask. Yeah. So LangChain's an open source framework for building agents. Yes. But, how did that get into this? 'Cause by default, a LangChain agent doesn't just magically appear in Agent 365, does it?

Graham Hosking: No, it doesn't. No. So there's a couple of different ways you can bring agents in. We've got this agent registry that you can see on the screen here. So in my demo account, I've got 386 agents. I've got some customers with, like, 5, 6,000, by the way. And then over here that you can see is I can explore other platforms. So the idea being is you can connect other third-party agents into a central registry in Agent 365, and we support four today, which is Amazon, Google, Databricks, and Salesforce. So you can just simply go into... Let's pick Google for a second, give it a region, and then your project IDs and your access keys, and then we can get a registry in here of all of the agents in those two platforms, Microsoft and Google. Right.

Tom Arbuthnot: Basically- And again, not magic here. This is just these- Yeah... these platforms have APIs and access, so if you have the right permissions across those platforms, this tool can go in, read across, and see what you're doing in that tool over there.

Graham Hosking: Exactly. But that's the important point, Tom, is it's showing you the agents and some associated metadata, but doesn't automatically give you full observability of that. So you have to have the Agent 365 SDKs infused in those pro code agents in order to get the observability. But we also have a number of partners as well, Microsoft partners we've been working with over the last couple of months, and they already have the Agent 365 SDKs built into them. So if you're using things like Manus, for example, or Lovable, guess what? It's got Agent 365 already. So you can see those types of agents that are being registered in your estate, and then you can see inside of those agents as well, even though they sit outside of Microsoft. That's so

Tom Arbuthnot: Cool. That, that's a really good tip because that, I mean, that's the, the reality of this agent space is not gonna all be on one platform. You're gonna have specialist ones from other-. -MSPs and ISVs. You're gonna have a certain division, busy building things on Salesforce or whatever it is. So like, like, saying how do we all play nice to give this layer of visibility is gonna be an interesting conversation.

Graham Hosking: It is, yeah, and that's where we brought in those maps as well. You mentioned about agent to agent. Like, it's not just agents inside of Microsoft that can talk to each other. You could have a Microsoft agent talking to a Google one, right? Because that has all the specialisms and, and, kind of persona and access to different tools. So the whole idea of these maps as well isn't just, like, a really nice UI, but it's showing you those, potential risks to other types of agents too. So these other ones are all my third-party agents that are built in LangChain and a few other, open source tools as well. Oh, by the way, Microsoft has Agent, Framework, Microsoft Agent Framework, which is open source. Just letting you know. And then we can see other types of agents as well, like we can see all of my Agent Builder ones. I can click into these as well to get additional telemetry on that, and that's where Agent 365 kicks in because then we can see not just who created this agent, a little bit more information about it, about it, but also the instructions, 'cause instructions can be manipulated too, right? So as these agents are being created in, your, your organization, your admins are going to be vetting all of this before it gets released to anyone in, in the organization. So it's very, very cool to kind of see this all in one place, 'cause traditionally you'd have to go over to the source of where the agent was created and then read it there.

Tom Arbuthnot: Yeah.

Graham Hosking: Not a good experience.

Tom Arbuthnot: And, and so this is really helpful is already, the, there, there's kind of a hierarchy here of, like, depth of visibility and control, which is, I guess- First party built on the Microsoft platform. A lot of this is working together. Yeah. Although even that shouldn't be an assumption, because things like, as my understanding is, like Scout hasn't got here yet, so presumably at some point- Not yet... Scout will have the Agent SDK, and it will be baked. Like, like it will be as, as close to this scenario. And then you've got the other extreme, which is like all the, the... In our Agent 365 world, we've got Agent registry, so we know something's there. We at least know what's there, but we'd have to go and talk to the owner of that agent on, and they'd tell us on that platform, unless the agent had the Agent 365 SDK all- Yes... all was baked in. Is that right?

Graham Hosking: Yeah, you're, you're right, as in any agents you build in the Microsoft platform, whether that's Agent Builder, Copilot Studio, or hosted agents in Foundry, like they already have the SDKs built in. You don't have to think about it. They just appear in here as a registry, and then you have full observability. Any agents that are built in pro code or in a third party, depending on the third party, like you might have to infuse those with the SDKs. In other cases, if you, Google on Bing of course, and go to 365 Showcase Yes It'll give you a list of all of the parties that are supported with Agent 365, those ones already infused.

Tom Arbuthnot: Yeah.

Graham Hosking: So you can see, see things like Adobe. We can see Atlassian products on here as well.

Tom Arbuthnot: A couple of keys- And it's, it's obviously a reasonable bet, and we see these coming up on the roadmap, like this will grow. Anybody, as E7 comes along and, you know, we're in the new Microsoft FY as we record this, like a lot of the organizations I'm talking about are looking at E7. Therefore- Yeah... when they go out shopping for solutions, they're gonna ask the ISVs, "Hey, do you plug in nicely to, Agent 365?"

Graham Hosking: Yeah. I think it's a key selling point as well. I think as these third parties are building their own agents, I think they gotta have some sort of, auditability or-... some sort of way of being able to see inside of a black box, right? Everybody knows that they can send prompts and get responses, but the important part is the chain of thought behind it. Like, why did that agent make that specific decision? Yeah. Especially in like highly regulated organizations where if they're audited and then an agent went a little bit rogue or gave the wrong answer, you have to be able to provide that type of information

Tom Arbuthnot: Otherwise- Is, is there any part of this conversation that is about agent improvement? 'Cause as you say that, it strikes me, it's interesting that actually we've got a really nice, set of understanding here to go back and improve the agent prompt and the agent experience. Is this mainly for audit, or is it being considered for actual, you know, process improvement in terms of the agent?

Graham Hosking: Not for process, not, not really for that type of use case. It is predominantly around the, the security, the auditability of those types of agents. But yeah, that, the information exists, right? So we're using- Yeah... things like the M365 audit log. We're using things like, eDiscovery in order to extract that information out. So potentially it could be used, but it- W-... it's not, it's finding use case.

Tom Arbuthnot: We've been doing that with the ChangePilot agent lately, and it's been really impressive. So we, it, it grabs the M365 messages and messages. It summarizes all of them, and then myself and others review them. We log every time the expert human reviewer changes something or disagrees, and then we go back a month later and we're like, "Hey, here's the database of all the human-made changes. How could we make the system prompt more robust?" Yes. And it'd be like, "Oh, I see. You keep changing this because of this phrase." So, th- we found that to be... And that's only recently we've been doing that, but that, that's been really useful for us because the diligence of the AI improving itself is way better than the, the person, me and the team in this case, going through change by change and working out why the system prompts steered it slightly this way- Yeah or slightly that way.

Graham Hosking: Yeah. That's more of the evaluations piece that we have in, in Copilot Studio, and there's capabilities as well over in Foundry when you're building agents there. So as you- Yeah... kind of change models and things or, let's say, you're monitoring for different And prompts that the end users have given- It, it'll be more that side then you can start to do that. Yeah. Slightly different to Agent 365 of course, but yeah, it's- Yeah... it's possible, and it's getting better all the time, you know. Something

Tom Arbuthnot: That was just- And talk, talk to me about licensing. So you're uniquely, happy to... suited to answer this question. Yeah. Yeah. Like also, I'm interested 'cause you look after some of the, ISV partners. Like- Mm-hmm... so for th- let's go there first. For them baking it into their third party products, is the Agent SDK just available to them to do that? Like there's no incremental charge on them for making their thing compatible with this, is that right?

Graham Hosking: Yeah, it... You're right. It's- It's a, a common misconception, not just with Agent 365 or other parts of the platform, that because, like an IT admin is going into the back end here and being able to see like what types of agents and things that they have, is that they're the ones that need to be licensed 'cause they're the one that's using it. That is not the case. Everything predominantly in M365 is done on an end user basis. So any user that is interacting with an agent or the agent and the user is benefiting from the full observability, they would have to have an Agent 365 license. So-

Tom Arbuthnot: And, and this is one of those things, and there's other things in the M365 workload here where I- I'll say this as independent, not as you at Microsoft, but like it's one of those- Yeah scenarios where benefiting from like, like there's a line being drawn there that isn't licensed enforced at the moment. But if, if you look at how the experience is being done, if your users are using these agents and they're being reported on in this tool, then they're gaining, but your organization is gaining benefit from that visibility is kind of the concept. Is that right?

Graham Hosking: That is correct, yeah. So these, these agent could be in the Microsoft ecosystem, they could be outside of it. But because they're infused of those Agent 365 SDKs, the end user has to be licensed. But that gives you flexibility as well, right? So I- in an ideal world, like everybody's gonna be using agents, whether they're pre-built ones like Researcher, Analyst or Scout or Cowork. But in some cases, at the moment, you might have a group of people that just don't use agents. So you don't have to license them for that. There's no technical enforcement of a license either, so it doesn't mean that, Tom, like you don't get an Agent 365 license, but that doesn't stop you from using an agent that is fully observed, so it is more of kind of a legal, licensing piece, just like we have over in other parts of, of the ecosystem like Purview.

Tom Arbuthnot: Your, your, your Purview world that you know well. Yeah, that's another one I feel like.

Graham Hosking: Yeah. See, like over in the Purview world, which is also relevant to agents, is you can like systematically find and automatically apply sensitivity labels, which can, not just add metadata to content, but also have encryption and permissions around that. Now- Like, it's the same principle, right? If you're doing that, you're creating that content, and it's automatically applying the sensitivity label, you're, you and the organization is benefiting from that. But if you're somebody on the front line where you're just reading those files and you're not, like, doing the creation of that, then those types of users don't need to be licensed with that enhanced license. So yeah, definitely speak to your Microsoft representative, and they can kind of guide you on where you need to go. But yeah, Agent

Tom Arbuthnot: 365. Yeah. And is it a bit like those other things, like the first license on the tenant lights this up?

Graham Hosking: Yeah.

Tom Arbuthnot: And, and-

Graham Hosking: One

Tom Arbuthnot: License lights- Then

Graham Hosking: You can start understanding it. Nice You'll know when you go into this Agent 365 interface, some of these elements like agent runtime and risks and things will be grayed out, and it'll say, "Hey, you need an Agent 365 license." But you just need one to light everything up, but that doesn't mean you're compliant. You still need to license your end users for that

Tom Arbuthnot: Yeah. And, and for the people doing, you know, for the organization listening in here, like, go, go get that seat to assess it and understand it right, because this conversation is absolutely coming to the business side of, "Oh, we're using agents now. What are our options? What are our visibility?" And, it, it's a good way to assess if it's, if there's value there for you.

Graham Hosking: Yeah. And there's some flexibility again with the licensing. Like, you can buy a standalone license. Ideally, the prereq of that, that is gonna be E5 because then it lights up all of the, the compliance and security elements in Defender and Purview. Like, without that you do get some insights to that, but it's not gonna give you everything that you need. But in that case, if you're considering things like E5 or you already have E5, and then you're looking at M365 Copilot and you're looking at Agent 365, it just makes sense to maybe step up. Why

Tom Arbuthnot: Not? Why

Graham Hosking: Not? Yeah. Maybe just step up to E7. Like, you don't have to buy all the licenses again- Yeah... if you're already on E5, you can just step up to that. But again, it's up to every individual organization about what they need and what they're gonna benefit from.

Tom Arbuthnot: Yeah. We've got a podcast coming up, actually. Ally at Norton Rose Fulbright, they're going E7, and she's coming on to talk about that journey. Yeah... 'cause that, I think that for this year, this Microsoft year, that's gonna be a big conversation with customers about when's the right time to step up to E7.

Graham Hosking: Yeah. S- it's, yeah, there're lot- lots of conversations to have, whether you're using things like Copilot today, which is kind of more the driver and makes sense, I think, to do the step up, or you're looking at from a security point of view because you're using agents that are outside the Microsoft ecosystem, that also makes sense, too. So I think there's different avenues. That's what I'm trying to say. I just wanted to finish off, Tom, with showing you just two more things that, that are coming in Frontier, which I think is also super powerful, and you'll see the trajectory about where Microsoft is heading in this more agentic world, is, a lot of my, my ISV customers are still building, in other platforms, not just Microsoft, but they're also building agents that are local. And you mentioned this earlier on, like Hermes and OpenClaw and Scout, like those agents can live on your local machine. So in Frontier at the moment, we're able to monitor for OpenClaw, so any devices that have they're installed Guess how this works? It works through Defender for Endpoint, right? So we can see what's happening there. But also there's gonna be a whole list of other third-party vendors as well, so we can monitor for those types of agents that wherever they're being created, that you can- Nice... have that full observability.

Tom Arbuthnot: I would definitely get the OpenClaw monitoring on, 'cause I'm pretty confident some people are experimenting on their, their corporate machines that possibly shouldn't be.

Graham Hosking: Quite possibly, yes. But how do you know unless you go- Yeah... have a look in that? And then lastly, around kinda tools, so you mentioned around deterministic and non-deterministic actions. We can build MCP tools now as, like, plugins as well in Copilot Cowork, and those plugins can have an MCP server, but also associated skills around that connectivity. And this is a central repository, just like we've got for agents, where we can see all of our agents that's being used. I as an IT admin can view all of the kinda first-party and third-party MCP and plugins too, and you can see I have some of these blocked. So I can block that at a tenant level if I decide, "Nope, nobody's got access to do that." Or if I decide I want a little bit more control, is I can go in and I can view all of the settings, understand what all these connections do. So here's all of the tools associated with this, WorkIQ Teams MCP server. So again, I can read and kind of vet that. But in the third-party ones, if I scroll right down the bottom, there's some third-party plugins that either admins can create as part of Cowork, or now end users will also be able to, create their plugins as well and submit those. So just like we do with agents, we want to vet that before it's sent out to, the, the rest of the organization. So I can see this TomTom Maps. I can see a link sent to an external URL. It's got some associated skills in here. Skills are just marked down files in natural language. So I want to vet whether these do something good or bad.

Tom Arbuthnot: Yeah.

Graham Hosking: And then I can choose who it's actually sent out to as well. So I could say all users, no users, or specific users and groups.

Tom Arbuthnot: Oh, that's really useful 'cause that's-... like, you know, we've invested in, another platform, you know, legal, we're using XYZ platform. We've got an MCP for it, but it's only for these people who've got the license, so I can show these people that plugin's available to them, but I don't wanna show it to the entire org 'cause they'll try and use it, and they're not licensed for that service anyway.

Graham Hosking: Yeah, I had a customer ask me yesterday, they were really frustrated in giving Copilot Studio to their end users, being able to turn off connectors, but he said there's thousands. So when end users go into Studio, and they can see all these thousands of connectors, the only way that they can find out that IT has blocked them is, like, clicking on one that doesn't seem to work. And like, yeah, not, not a brilliant, like, user interface for that, but because there's thousands, you just can't, like, hide them all, and I said it works both ways. Like, if you blocked everything, and they can only see f- three or four-

Tom Arbuthnot: They

Graham Hosking: Don't know what those possibles- They don't know what else is available. Yeah.

Tom Arbuthnot: So yeah, it, it works. It's all right. Get a computer use agent to click them one by one and build a-... build a database and-

Graham Hosking: No. No. Awesome.

Tom Arbuthnot: So

Graham Hosking: There we go.

Tom Arbuthnot: That's so useful. Great. Well, that was... Again, you've decoded that wonderfully. Thank you. Thank you... let's, let's, w- bonus time, show me your cool, agent demo.

Graham Hosking: Yeah, sure. So I talked about the- The digital coworkers. So I started building off Cassidy, that you've already met now, which was an operations manager. And then, this was built on, on part of different conversations I was having with customers. And when I was trying to tell them about what a digital coworker was, there was nothing to show them, right? So in the AI industry, you may already know this, Tom, and other people listening, is, there's another product called Obsidian, and people were using Obsidian to create their own notes and then creating a second brain. And I quite like the visual of that second brain because it was, like, populating and showing, all of the kind of notes and the similarities and connections of that. And I said, "Wouldn't that be cool if we created a fully autonomous agent, but we could see it thinking, like, see its brain?" So this is Morgan, which is a digital CFO. So you can see up here that they work nine to five they could work twenty-four seven, but I don't, so I don't want them call- calling me in the night. But these are all the connections that this fully autonomous agent is thinking about in real time. It's super cool, right? That's awesome. And now I can s- see all of these elements, where it's thinking about individual people that it works with. This could be customers or internal stakeholders, of course. We can also have a little bit of a filter here as well to see all of the governance elements about how it kind of governs itself, what policies and what, actions it's going to take. And then we can also see these agent swarms as well, where it talks to other fully autonomous agents to do its role. So like a digital CFO might talk to a CO- a COO. And these aren't designed to replace people in the business. They're designed to kind of augment them, like go away and do the work that I have to do on a daily basis, but actually own that end-to-end process. And I then I was thinking about, like, other ways that we have kind of talked to human beings in the past, like Microsoft Teams is one of them. And I, I haven't got time to show you today, but Morgan can actually see my availability on Teams, and it can actually decide to call me directly. So I can have a voice interaction over Teams with this fully autonomous agent. And they may reach out and say, "Hey, I've got a problem with, maybe our, our figures for this month, maybe our sales, our pipeline's down. I, I need some actions about what we're gonna do to fix that." So you can have that, back and forth, interaction. And then on the flip side of that thought process was like when a human needs to be in the loop to make a financial decision, like, we don't want these autonomous agents to do any of that. So I kinda coined the phrase as in autonomous internally, like internally of the agent's scope, but then gated externally. So any financial decision, any kind of external communications this type of agent needs to perform is gated and stopped as part of that.

Tom Arbuthnot: I love that as a paradigm actually- Thank you 'cause the internal, internal makes sense. But also like just to like use cases I've approved and like, like in, in, you know, media creation world, like, like- Draft the script, write the script, generate the video, but publishing, that's gated, you know.

Graham Hosking: It's all gated, yeah. And there's gated in a way that Morgan isn't one agent. Morgan is eight agents. So it, it's gated as part of that internal process as well. Anyway, I could talk about this for hours. There's some other things in here as well where we can look in real time the, the ROI of that type of agent based on costs of it. That sits in Azure, of course. The full observability layer, so it's got that Agent 365 SDK built into it. That's how I could see Cassidy doing things I didn't really want it to do.

Tom Arbuthnot: Yeah.

Graham Hosking: But also for executives, right, they don't want to be called on Teams. Executives want to just go somewhere and ask some really quick, direct questions and get an answer back. So I built some avatars in collaboration with, a Microsoft partner called, DID, and we were building up these humanistic or humanoid avatars to have that quick conversation. So I'm just gonna let this run a second. Hi there, Morgan. How are you?

Video: Hello, I'm Morgan, your digital finance analyst. I'm here and ready to assist. How can I help you today?

Graham Hosking: Hi, Morgan. I was just wondering on the latest P&L. Can you give me the latest figures, please?

Tom Arbuthnot: You know, you see it on, on Hermes and OpenClaw and Scout, you see the dot, dot, dot of it. Like, the, the equivalent of you just have the typing is effectively now processing.

Video: Here are the latest P&L figures for July 2026. Revenue, $5.08 million. Gross margin, 62.96%. EBITDAA, $1.88 million. Cash, runway 2.9 months. Let me know if you'd like a deeper breakdown or additional insights.

Graham Hosking: So the, the whole purpose of this, you're right, I'll work on the pauses by the way, but it's doing a hell of a lot of stuff in the background. That's the whole reason of that visual by the way, is you could see- Yeah... all of the things it's trying to think about. Is, is people, have accessibility needs as well, like great for like CFOs that just wanna have a human interaction, very different to how we work with agents today, right, via text or voice. But also these avatars are lip syncing as well. So if I'm hard of hearing, I can lip sync or, or see the lip sync of the actual avatar. And I've got a different version of this as well, so if you... You're sight impaired, then I have large text or kind of changing the, the, text as well so it's more bold, actually read that out for you, and those visual cues as well I mentioned earlier on. So just a different way of interacting with these fully autonomous AI teammates, and they're kind of building in the different modalities about how we interact with the world and humans today.

Tom Arbuthnot: So- That's awesome. I see-... that's why let me show

Graham Hosking: You this.

Tom Arbuthnot: No, no, that's awesome. We've got a... it'll probably been out by the time we, put this podcast out, but we're doing a webinar all around the voice agents or voice agent options, so we'll dig in, dig in a bit more on that. But seeing this is super impressive, and I, I love that you've shown you can build agents on different platforms, open source frameworks, and with that Agent 365 SDK, bring that visibility back in. 'Cause I think that's one of the missing pieces in the marketing story for me, is understanding practically how it works- Yeah... in a multi-platform environment.

Graham Hosking: Yeah, bringing it all together. Like I said, Morgan is actually built on LangChain, sat in Azure, connected to the Microsoft IQ APIs using a Microsoft partner for the avatar. So yeah, you know, there's... The world's your oyster these days. You can build and combine everything you want. The world is now a big Meccano set, if you used to use Meccano, or a big Lego set maybe.

Tom Arbuthnot: Yeah. Awesome. Graham, thanks so much. Catch you again soon.

Graham Hosking: Yeah. Thanks very much.