Skip to Content
Cowork (Agentic AI)Agent 365 Tools and MCP Server Governance Baseline

Agent 365 Tools and MCP Server Governance Baseline

TL;DR: This skill reads the Microsoft Agent 365 Tools page to list available and blocked MCP servers, reviews pending bring-your-own (BYO) MCP requests, and checks that Microsoft Defender’s AI agent inventory shows each agent’s MCP servers and tools. It changes nothing.

What does the Agent 365 tools governance baseline cover?

Microsoft Agent 365 is the control plane that lets administrators discover, govern and secure AI agents, and its Tools page in the Microsoft 365 admin centre governs which MCP servers, plugins, skills and connectors agents can use, and this skill inventories that registry, pending requests and Defender’s agent inventory without changing anything.

Microsoft Agent 365 has been generally available for the Commercial segment since 1 May 2026. On the Tools page, the Registry tab lists each tool with a status of Available or Blocked, and the Requests tab (labelled preview by Microsoft) holds pending approvals. If an MCP server is blocked, it is blocked for every user and every agent. A developer registers a BYO MCP server with the Agent 365 CLI; an administrator then approves or rejects it and consents to the Microsoft Entra permissions it needs. BYO MCP server registration is in preview. Microsoft Defender lists each agent’s MCP servers and tools in its AI agent inventory. This skill produces the MCP server governance baseline and flags gaps.

When should you run this skill?

Run this skill in Microsoft 365 admin centre tenants using Microsoft Agent 365 whenever you need evidence of which MCP servers agents can call, before granting developers access, after a new bring-your-own (BYO) MCP request arrives, or when reviewing agent tooling for a governance or audit request.

  • “Audit which MCP servers are available or blocked in our tenant”
  • “Review all pending BYO MCP server approval requests”
  • “Check whether developers have submitted MCP servers we have not reviewed”
  • “Check Defender’s AI agent inventory shows the MCP servers each agent uses”
  • “Produce AI tooling governance evidence for an audit”
  • “Establish our Agent 365 tools baseline before granting developer access”

How this skill works, step by step

  1. Sign in to the Microsoft 365 admin centre at admin.microsoft.com with an AI Administrator or Global Administrator role
  2. Go to Agents → Tools → Registry (the Agent 365 tools registry)
  3. Export or record the full MCP server list:
    • Filter by Publisher to separate Microsoft-published servers from other publishers
    • For each server, note name, type, publisher and status (Available or Blocked)
    • Open a server’s overview pane and its Tools tab to record the tools it exposes, where the server supports tool discovery
  4. For each Available MCP server: verify that the exposed tools align with business need; flag any server with broad data-access or write tools (for example file write or email send) that has not had a formal risk review
  5. Open Agents → Tools → Requests and, for each pending MCP request, record the server name, publisher, requester, request date and declared tools; escalate to the business owner for an approve or reject decision
  6. Compare each server’s current tool list against your last baseline (tool-level allow and block controls are rolling out for supported MCP servers; BYO support is planned)
  7. Open the Microsoft Defender portal → Assets → AI agents → Agents: verify that each agent shows its MCP servers, discovered tools and identity information
  8. Flag agents with no MCP server or tool information (a potential visibility gap)
  9. In Defender, open Settings → Security for AI → Policies & rules → Real-time protection: record whether custom blocking rules exist beyond the built-in Default rule, which only audits
  10. Optionally, use Defender advanced hunting (CloudAppEvents where ActionType is ExecuteToolByGateway) to compare actual tool invocations against the approved list
  11. Produce the MCP server inventory and governance summary below

Output format

The rows below are illustrative examples only. Replace them with your tenant’s data.

MCP server catalogue

MCP serverPublisherStatusTools exposedLast reviewedRisk
Work IQ MailMicrosoftAvailableCreate, update and delete messages; reply; semantic searchCurrentMedium — write actions
Work IQ CalendarMicrosoftAvailableCreate, list, update and delete events; accept and declineCurrentMedium — write actions
Contoso-CRM-Connector (example)BYOPending requestRead customer records, update CRMNever reviewedHigh — pending, external data

Governance summary

  • Total MCP servers in registry: N (Microsoft-published: N, other publishers: N)
  • Available: N | Blocked: N | Pending requests: N
  • BYO MCP servers never formally reviewed: N
  • MCP servers with broad data-access or write tools: N
  • Agents in Defender with no MCP server or tool information: N
  • Custom real-time protection blocking rules in Defender: Yes / No
  • Recommended actions: set an internal target for reviewing pending BYO requests; block MCP servers with unexplained broad tool access; investigate agents with no MCP server information in Defender

Scope and safety

Read-only — this skill does NOT:

  • Approve, reject, block or unblock MCP servers
  • Change tool-level enable or disable settings
  • Grant or modify Microsoft Entra permission consent for MCP servers
  • Change agent configurations, policies or real-time protection rules in Defender
  • Register, republish or delete BYO MCP servers

Licensing and permissions

Licences and add-ons

Capability usedLicence requirement (per Microsoft Learn)
Control which tools agents can access tenant-wide (Microsoft 365 admin centre)Microsoft 365 E7 or Microsoft Agent 365
Defender agent misconfiguration and exposure risks, relationship mapping for local agents (agent to devices, MCP servers), and blocking of tool invocationsMicrosoft 365 E7 or Microsoft Agent 365
BYO MCP server registration and approval workflow (preview)Microsoft does not document a separate licence for this on the cited pages; approval needs an AI Administrator or Global Administrator

Microsoft Agent 365 is a per-user licence, available as a stand-alone subscription and included with Microsoft 365 E7. Check Microsoft’s current pricing page for the price; this page does not quote one.

Least-privilege roles

  • AI Administrator or Global Administrator: the two roles Microsoft documents as able to open the Tools page, review MCP requests and grant tenant-wide consent
  • A Defender role that can read the AI agents inventory: this page has not confirmed which built-in role is the least-privileged option, so check Microsoft Defender role documentation before assigning one

Programmatic access

  • Approval and blocking are performed in the Microsoft 365 admin centre; this skill relies on the portal UI
  • Defender advanced hunting (CloudAppEvents, AgentsInfo) can supplement the portal view for tool-invocation and agent inventory evidence

Sources

Reviewed 2026-09-30 against the pages below. Microsoft does not document a price on these pages, so none is quoted.


Licensed under CC BY 4.0  by EDUC4TE .

SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload
▸ View skill file
How to use this skill
  1. Get the file. Download or copy the SKILL.md from the SKILL.md panel on this page.
  2. Load it into your host:
    • Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
    • Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
    • Any chat host — paste the file contents as your prompt.
  3. Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
  4. Provide your tenant scope and run it (a site, a collection, or the whole tenant).
  5. Review the report and action the risk-ranked recommendations.

This skill is read-only by default — it inspects and reports, and never changes your tenant.

Get SKILL.md

Last reviewed 2026-09-30 · Published 2026-06-22

Last updated on