Agent 365 Tools and MCP Server Governance Baseline
TL;DR: This skill reads the Microsoft Agent 365 Tools page to list available and blocked MCP servers, reviews pending bring-your-own (BYO) MCP requests, and checks that Microsoft Defender’s AI agent inventory shows each agent’s MCP servers and tools. It changes nothing.
What does the Agent 365 tools governance baseline cover?
Microsoft Agent 365 is the control plane that lets administrators discover, govern and secure AI agents, and its Tools page in the Microsoft 365 admin centre governs which MCP servers, plugins, skills and connectors agents can use, and this skill inventories that registry, pending requests and Defender’s agent inventory without changing anything.
Microsoft Agent 365 has been generally available for the Commercial segment since 1 May 2026. On the Tools page, the Registry tab lists each tool with a status of Available or Blocked, and the Requests tab (labelled preview by Microsoft) holds pending approvals. If an MCP server is blocked, it is blocked for every user and every agent. A developer registers a BYO MCP server with the Agent 365 CLI; an administrator then approves or rejects it and consents to the Microsoft Entra permissions it needs. BYO MCP server registration is in preview. Microsoft Defender lists each agent’s MCP servers and tools in its AI agent inventory. This skill produces the MCP server governance baseline and flags gaps.
When should you run this skill?
Run this skill in Microsoft 365 admin centre tenants using Microsoft Agent 365 whenever you need evidence of which MCP servers agents can call, before granting developers access, after a new bring-your-own (BYO) MCP request arrives, or when reviewing agent tooling for a governance or audit request.
- “Audit which MCP servers are available or blocked in our tenant”
- “Review all pending BYO MCP server approval requests”
- “Check whether developers have submitted MCP servers we have not reviewed”
- “Check Defender’s AI agent inventory shows the MCP servers each agent uses”
- “Produce AI tooling governance evidence for an audit”
- “Establish our Agent 365 tools baseline before granting developer access”
How this skill works, step by step
- Sign in to the Microsoft 365 admin centre at
admin.microsoft.comwith an AI Administrator or Global Administrator role - Go to Agents → Tools → Registry (the Agent 365 tools registry)
- Export or record the full MCP server list:
- Filter by Publisher to separate Microsoft-published servers from other publishers
- For each server, note name, type, publisher and status (Available or Blocked)
- Open a server’s overview pane and its Tools tab to record the tools it exposes, where the server supports tool discovery
- For each Available MCP server: verify that the exposed tools align with business need; flag any server with broad data-access or write tools (for example file write or email send) that has not had a formal risk review
- Open Agents → Tools → Requests and, for each pending MCP request, record the server name, publisher, requester, request date and declared tools; escalate to the business owner for an approve or reject decision
- Compare each server’s current tool list against your last baseline (tool-level allow and block controls are rolling out for supported MCP servers; BYO support is planned)
- Open the Microsoft Defender portal → Assets → AI agents → Agents: verify that each agent shows its MCP servers, discovered tools and identity information
- Flag agents with no MCP server or tool information (a potential visibility gap)
- In Defender, open Settings → Security for AI → Policies & rules → Real-time protection: record whether custom blocking rules exist beyond the built-in Default rule, which only audits
- Optionally, use Defender advanced hunting (
CloudAppEventswhereActionTypeisExecuteToolByGateway) to compare actual tool invocations against the approved list - Produce the MCP server inventory and governance summary below
Output format
The rows below are illustrative examples only. Replace them with your tenant’s data.
MCP server catalogue
| MCP server | Publisher | Status | Tools exposed | Last reviewed | Risk |
|---|---|---|---|---|---|
| Work IQ Mail | Microsoft | Available | Create, update and delete messages; reply; semantic search | Current | Medium — write actions |
| Work IQ Calendar | Microsoft | Available | Create, list, update and delete events; accept and decline | Current | Medium — write actions |
| Contoso-CRM-Connector (example) | BYO | Pending request | Read customer records, update CRM | Never reviewed | High — pending, external data |
Governance summary
- Total MCP servers in registry: N (Microsoft-published: N, other publishers: N)
- Available: N | Blocked: N | Pending requests: N
- BYO MCP servers never formally reviewed: N
- MCP servers with broad data-access or write tools: N
- Agents in Defender with no MCP server or tool information: N
- Custom real-time protection blocking rules in Defender: Yes / No
- Recommended actions: set an internal target for reviewing pending BYO requests; block MCP servers with unexplained broad tool access; investigate agents with no MCP server information in Defender
Scope and safety
Read-only — this skill does NOT:
- Approve, reject, block or unblock MCP servers
- Change tool-level enable or disable settings
- Grant or modify Microsoft Entra permission consent for MCP servers
- Change agent configurations, policies or real-time protection rules in Defender
- Register, republish or delete BYO MCP servers
Licensing and permissions
Licences and add-ons
| Capability used | Licence requirement (per Microsoft Learn) |
|---|---|
| Control which tools agents can access tenant-wide (Microsoft 365 admin centre) | Microsoft 365 E7 or Microsoft Agent 365 |
| Defender agent misconfiguration and exposure risks, relationship mapping for local agents (agent to devices, MCP servers), and blocking of tool invocations | Microsoft 365 E7 or Microsoft Agent 365 |
| BYO MCP server registration and approval workflow (preview) | Microsoft does not document a separate licence for this on the cited pages; approval needs an AI Administrator or Global Administrator |
Microsoft Agent 365 is a per-user licence, available as a stand-alone subscription and included with Microsoft 365 E7. Check Microsoft’s current pricing page for the price; this page does not quote one.
Least-privilege roles
- AI Administrator or Global Administrator: the two roles Microsoft documents as able to open the Tools page, review MCP requests and grant tenant-wide consent
- A Defender role that can read the AI agents inventory: this page has not confirmed which built-in role is the least-privileged option, so check Microsoft Defender role documentation before assigning one
Programmatic access
- Approval and blocking are performed in the Microsoft 365 admin centre; this skill relies on the portal UI
- Defender advanced hunting (
CloudAppEvents,AgentsInfo) can supplement the portal view for tool-invocation and agent inventory evidence
Related skills
- Governing AI Agents in Microsoft 365: Start here for the agent governance sequence.
- Agent 365 Registry and Shadow AI Discovery: Run before, to compare registered agents with unmanaged agents found on endpoints.
- Copilot Studio Agent Inventory and Connector Audit: Run before, to see each Copilot Studio agent with its connectors and knowledge sources.
- Work IQ API Access and Tool Call Governance Audit: Run after, to audit which agents hold Work IQ API grants.
- Governing Microsoft 365 Copilot with Microsoft Purview: Read after, for the Microsoft Purview controls that apply to Microsoft 365 Copilot.
Sources
Reviewed 2026-09-30 against the pages below. Microsoft does not document a price on these pages, so none is quoted.
- Overview of the Tools page in Microsoft 365 admin center (Microsoft Learn)
- Manage plugins, skills, and MCP servers (Microsoft Learn)
- Bring your own (BYO) MCP server (Microsoft Learn)
- Work IQ MCP overview (Microsoft Learn)
- Overview of Microsoft Agent 365 (Microsoft Learn)
- Microsoft Agent 365 service description (Microsoft Learn)
- Discover AI agents and assess security posture using Microsoft Defender (Microsoft Learn)
- Protect AI agents in real time using Microsoft Defender (Microsoft Learn)
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30 · Published 2026-06-22