top of page

LATEST INSIGHTS

Expert insights across your SaaS environment

Blogs and papers from the SAASiQ team on enterprise SaaS, cloud and AI.

Microsoft Launches Agent 365 as Security Bodies Set Out Controls for AI Agents

Writer: SAASiQ.ai
SAASiQ.ai
May 6
6 min read

Updated: 6 days ago

Title: Microsoft Launches Agent 365 as Security Bodies Set Out Controls for AI Agents

Date: 6 May 2026

Type: Blog

Author: SAASiQ (contact@saasiq.ai)

Word count: 1485 words

Reading time: 6 min

Published: 06-05-2026


Microsoft made Agent 365, its registry and control system for AI agents, generally available on 1 May at $15 per user per month. Two days earlier the Cloud Security Alliance said its new AI foundation had been authorised as a CVE Numbering Authority and had taken over two specifications for controlling what agents do at runtime. In Brussels, talks on delaying the EU AI Act's high-risk rules ended on 28 April without agreement, so 2 August 2026 is still the legal start date.


Agent 365 and Entra

Agent 365 is Microsoft's inventory and control layer for agents running on devices, in the cloud and inside SaaS applications. Identity comes from Microsoft Entra, which handles agent credentials and access controls, and administrators can start, stop and delete agents across platforms and set policies on what they are allowed to do. It also maps which devices, MCP servers and cloud resources each agent can reach.


Microsoft licenses it per person rather than per agent: one licence for each person who manages, sponsors or uses agents, either standalone at $15 a month or as part of Microsoft 365 E7. Registry sync with AWS Bedrock and Google Cloud is in public preview, and Entra's network controls now extend to local agents such as OpenClaw and Claude Code. Microsoft said runtime blocking of malicious agent behaviour would follow in June.


Separation of duties in Oracle Fusion

Separation of duties in an ERP system rests on splitting sensitive steps between different people. Oracle's own documentation gives the standard example: an access check that looks for users who hold the privileges both to create a payables invoice and to approve payment on it, and a transaction check that finds occasions when one user has actually done both. Its Risk and Security Snapshot Report, part of Oracle Fusion Cloud Risk Management, runs both kinds of analysis with prebuilt algorithms, grouped into content packs by business process, and also flags roles that grant elevated access on their own.


Agents built in Oracle AI Agent Studio, which Oracle launched in March 2025, sit inside that same model. Oracle said at launch that AI Agent Studio adheres to Fusion security configurations, policies and access controls, so administrators and end users see only the data and functions their roles allow. An agent working for a user gets no more access than the user already has. SAASiQ's view is that, for Fusion agents, separation of duties therefore comes down mostly to the roles of the people they run for, which existing SoD analysis already covers.


Oracle has also put an agent into the access process itself. The Access Request Assistant, added in release 25D, lets a user ask in plain language for ERP roles and for the data-access security contexts set in Manage Data Access for Users, without knowing the role names. Once the request is created, the agent starts the Advanced Access Request workflow, which runs the separation-of-duties analysis before anything is granted. The organisation's role-mapping document, which maps its personas to roles, has to be added as a tool for the agent. Release 26B adds a real-time reporting subject area for access requests, covering request volumes, approval times, policy violations and outcomes.


Below the applications, Oracle announced Deep Data Security on 24 March as part of Oracle AI Database 26ai. It passes the identity of the end user, or of an agent acting for one, to the database at runtime, and the database applies row, column and cell policies to every query and audits the activity.


The OWASP list for agents

The OWASP GenAI Security Project published its Top 10 for Agentic Applications on 9 December 2025, written by more than 100 security researchers and practitioners. The ten run from ASI01, Agent Goal Hijack, to ASI10, Rogue Agents, and cover supply chain, code execution, memory poisoning, communication between agents and cascading failures in between.


Three of them map directly onto finance and HR systems. Agent Goal Hijack (ASI01) is an attacker changing an agent's objectives or decision path through malicious content it reads. Tool Misuse and Exploitation (ASI02) is an agent using a legitimate tool in an unsafe or unintended way, leading to data exfiltration or a hijacked workflow. Identity and Privilege Abuse (ASI03) covers an agent acting with more authority than it should have, or on old credentials.


Auth0's summary of the list, published in February, describes the principle behind it as least agency: an agent's autonomy is limited by approval steps and credentials scoped to the task, on top of the usual least-privilege limits on what it can reach.


Agent identity at NIST and the CSA

NIST's National Cybersecurity Center of Excellence published a concept paper on 5 February, 'Accelerating the Adoption of Software and AI Agent Identity and Authorization', with comments closing on 2 April. It proposes a demonstration project using commercial products and names the standards likely to be involved: OAuth and OpenID Connect, SCIM for identity lifecycle, SPIFFE and SPIRE, and attribute-based access control including Next Generation Access Control. Its questions include how agents should be identified, whether an agent's identity should be persistent or tied to a single task, and how a compromised agent's credentials are revoked. As Biometric Update reported it, the paper wants every agent action traceable to the non-human identity that performed it and to the person who delegated the permissions.


NIST's Center for AI Standards and Innovation launched a wider AI Agent Standards Initiative on 17 February, covering industry standards, open-source protocols and research into agent security and identity. It followed a request for information on AI agent security published on 8 January, which closed on 9 March.


The Cloud Security Alliance launched CSAI, a non-profit foundation for AI security, at RSAC 2026 on 23 March, with the stated mission of 'securing the agentic control plane': identity for non-human actors, authorisation and privilege governance, orchestration, runtime behaviour and trust assurance. On 29 April it added the CVE authorisation, took over the Autonomous Action Runtime Management specification (contributed by Vanta) and the Agentic Trust Framework (from Josh Woodruff of MassiveScale.AI), and set out a four-phase STAR for AI Catastrophic Risk Annex running from June 2026 to December 2027. CSA's AI Controls Matrix, released in July 2025, had 243 control objectives across 18 domains.


The Model Context Protocol, which Anthropic published in November 2024 and handed to the Linux Foundation's new Agentic AI Foundation on 9 December 2025, handles part of this. Since the June 2025 revision of the specification, an MCP server acts as an OAuth resource server and must validate the access tokens it is given. That settles whether a client may connect to a server on a user's behalf. What the agent may then do is decided by the server and the application behind it, which in Fusion's case means its role and data security.


Gartner's cancellation forecast

Gartner said on 25 June 2025 that it expected more than 40 per cent of agentic AI projects to be cancelled by the end of 2027 because of escalating costs, unclear business value or inadequate risk controls. Anushree Verma, a senior director analyst, said most projects were early experiments or proofs of concept driven by hype.


The same research estimated that only about 130 of the thousands of vendors selling agentic products offered real agentic features, and described the rest as 'agent washing', the rebranding of assistants, robotic process automation and chatbots. In a Gartner poll of 3,412 webinar attendees in January 2025, 19 per cent said their organisation had made significant investments in agentic AI, 42 per cent conservative ones and 8 per cent none, with 31 per cent waiting or unsure.


The EU AI Act date

The European Commission published the Digital Omnibus on AI on 19 November 2025, proposing to defer the Act's high-risk obligations. By late April the Commission, Parliament and Council had converged on 2 December 2027 for the stand-alone high-risk systems in Annex III and 2 August 2028 for AI in products covered by Annex I.


The second political trilogue on 28 April ended without agreement after about 12 hours. The dispute was over how AI in products already regulated under sectoral law, such as machinery and medical devices, should be assessed for conformity, and the delay itself was not the sticking point. Until an amendment is agreed and adopted, the original date of 2 August 2026 stands.


Annex III includes AI used in recruitment, promotion and termination decisions, task allocation and monitoring of workers, and credit scoring of individuals, so agents working in HCM modules can fall within it. Organisations deploying a high-risk system have to assign human oversight and keep the logs it generates.


Next dates

Microsoft's runtime blocking for Agent 365 is due in June, the first phase of the CSA's catastrophic risk annex runs from June to September, and the EU high-risk obligations apply from 2 August 2026 unless the Omnibus is agreed and adopted before then.

SAASiQ - Intelligent Solutions for SaaS ©

Optimise your SaaS licences and software subscriptions with SAASiQ

bottom of page