---
name: Agent 365 Tools and MCP Server Governance Baseline
description: "Audit the Agent 365 tools catalogue: available and blocked MCP servers, pending BYO MCP requests and per-agent tools in Defender, for a governed baseline."
lastReviewed: 2026-09-30
---

# Agent 365 Tools and MCP Server Governance Baseline

> **TL;DR:** This skill reads the Microsoft Agent 365 Tools page to list available and blocked MCP servers, reviews pending bring-your-own (BYO) MCP requests, and checks that Microsoft Defender's AI agent inventory shows each agent's MCP servers and tools. It changes nothing.

## What does the Agent 365 tools governance baseline cover?

Microsoft Agent 365 is the control plane that lets administrators discover, govern and secure AI agents, and its Tools page in the Microsoft 365 admin centre governs which MCP servers, plugins, skills and connectors agents can use, and this skill inventories that registry, pending requests and Defender's agent inventory without changing anything.

Microsoft Agent 365 has been generally available for the Commercial segment since 1 May 2026. On the Tools page, the **Registry** tab lists each tool with a status of **Available** or **Blocked**, and the **Requests** tab (labelled preview by Microsoft) holds pending approvals. If an MCP server is blocked, it is blocked for every user and every agent. A developer registers a BYO MCP server with the Agent 365 CLI; an administrator then approves or rejects it and consents to the Microsoft Entra permissions it needs. BYO MCP server registration is in preview. Microsoft Defender lists each agent's MCP servers and tools in its AI agent inventory. This skill produces the MCP server governance baseline and flags gaps.

## When should you run this skill?

Run this skill in Microsoft 365 admin centre tenants using Microsoft Agent 365 whenever you need evidence of which MCP servers agents can call, before granting developers access, after a new bring-your-own (BYO) MCP request arrives, or when reviewing agent tooling for a governance or audit request.

- "Audit which MCP servers are available or blocked in our tenant"
- "Review all pending BYO MCP server approval requests"
- "Check whether developers have submitted MCP servers we have not reviewed"
- "Check Defender's AI agent inventory shows the MCP servers each agent uses"
- "Produce AI tooling governance evidence for an audit"
- "Establish our Agent 365 tools baseline before granting developer access"

## How this skill works, step by step

1. Sign in to the Microsoft 365 admin centre at `admin.microsoft.com` with an AI Administrator or Global Administrator role
2. Go to **Agents** → **Tools** → **Registry** (the Agent 365 tools registry)
3. Export or record the full MCP server list:
   - Filter by **Publisher** to separate Microsoft-published servers from other publishers
   - For each server, note name, type, publisher and status (**Available** or **Blocked**)
   - Open a server's overview pane and its **Tools** tab to record the tools it exposes, where the server supports tool discovery
4. For each Available MCP server: verify that the exposed tools align with business need; flag any server with broad data-access or write tools (for example file write or email send) that has not had a formal risk review
5. Open **Agents** → **Tools** → **Requests** and, for each pending MCP request, record the server name, publisher, requester, request date and declared tools; escalate to the business owner for an approve or reject decision
6. Compare each server's current tool list against your last baseline (tool-level allow and block controls are rolling out for supported MCP servers; BYO support is planned)
7. Open the Microsoft Defender portal → **Assets** → **AI agents** → **Agents**: verify that each agent shows its MCP servers, discovered tools and identity information
8. Flag agents with no MCP server or tool information (a potential visibility gap)
9. In Defender, open **Settings** → **Security for AI** → **Policies & rules** → **Real-time protection**: record whether custom blocking rules exist beyond the built-in Default rule, which only audits
10. Optionally, use Defender advanced hunting (`CloudAppEvents` where `ActionType` is `ExecuteToolByGateway`) to compare actual tool invocations against the approved list
11. Produce the MCP server inventory and governance summary below

## Output format

The rows below are illustrative examples only. Replace them with your tenant's data.

### MCP server catalogue

| MCP server | Publisher | Status | Tools exposed | Last reviewed | Risk |
| --- | --- | --- | --- | --- | --- |
| Work IQ Mail | Microsoft | Available | Create, update and delete messages; reply; semantic search | Current | Medium — write actions |
| Work IQ Calendar | Microsoft | Available | Create, list, update and delete events; accept and decline | Current | Medium — write actions |
| Contoso-CRM-Connector (example) | BYO | Pending request | Read customer records, update CRM | Never reviewed | High — pending, external data |

### Governance summary

- Total MCP servers in registry: N (Microsoft-published: N, other publishers: N)
- Available: N | Blocked: N | Pending requests: N
- BYO MCP servers never formally reviewed: N
- MCP servers with broad data-access or write tools: N
- Agents in Defender with no MCP server or tool information: N
- Custom real-time protection blocking rules in Defender: Yes / No
- Recommended actions: set an internal target for reviewing pending BYO requests; block MCP servers with unexplained broad tool access; investigate agents with no MCP server information in Defender

## Scope and safety

Read-only — this skill does NOT:

- Approve, reject, block or unblock MCP servers
- Change tool-level enable or disable settings
- Grant or modify Microsoft Entra permission consent for MCP servers
- Change agent configurations, policies or real-time protection rules in Defender
- Register, republish or delete BYO MCP servers

## Licensing and permissions

### Licences and add-ons

| Capability used | Licence requirement (per Microsoft Learn) |
| --- | --- |
| Control which tools agents can access tenant-wide (Microsoft 365 admin centre) | Microsoft 365 E7 or Microsoft Agent 365 |
| Defender agent misconfiguration and exposure risks, relationship mapping for local agents (agent to devices, MCP servers), and blocking of tool invocations | Microsoft 365 E7 or Microsoft Agent 365 |
| BYO MCP server registration and approval workflow (preview) | Microsoft does not document a separate licence for this on the cited pages; approval needs an AI Administrator or Global Administrator |

Microsoft Agent 365 is a per-user licence, available as a stand-alone subscription and included with Microsoft 365 E7. Check Microsoft's current pricing page for the price; this page does not quote one.

### Least-privilege roles

- AI Administrator or Global Administrator: the two roles Microsoft documents as able to open the Tools page, review MCP requests and grant tenant-wide consent
- A Defender role that can read the AI agents inventory: this page has not confirmed which built-in role is the least-privileged option, so check Microsoft Defender role documentation before assigning one

### Programmatic access

- Approval and blocking are performed in the Microsoft 365 admin centre; this skill relies on the portal UI
- Defender advanced hunting (`CloudAppEvents`, `AgentsInfo`) can supplement the portal view for tool-invocation and agent inventory evidence

## Related skills

- [Governing AI Agents in Microsoft 365](/cowork/agent-governance-guide): Start here for the agent governance sequence.
- [Agent 365 Registry and Shadow AI Discovery](/cowork/agent365-registry-shadow-ai-discovery): Run before, to compare registered agents with unmanaged agents found on endpoints.
- [Copilot Studio Agent Inventory and Connector Audit](/cowork/copilot-studio-agent-inventory): Run before, to see each Copilot Studio agent with its connectors and knowledge sources.
- [Work IQ API Access and Tool Call Governance Audit](/cowork/work-iq-api-access-audit): Run after, to audit which agents hold Work IQ API grants.
- [Governing Microsoft 365 Copilot with Microsoft Purview](/purview/copilot-governance-guide): Read after, for the Microsoft Purview controls that apply to Microsoft 365 Copilot.

## Sources

Reviewed 2026-09-30 against the pages below. Microsoft does not document a price on these pages, so none is quoted.

- [Overview of the Tools page in Microsoft 365 admin center (Microsoft Learn)](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-tools-for-agent)
- [Manage plugins, skills, and MCP servers (Microsoft Learn)](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-plugins-skills-mcp-servers)
- [Bring your own (BYO) MCP server (Microsoft Learn)](https://learn.microsoft.com/en-us/microsoft-365/admin/manage/manage-byo-mcp-server)
- [Work IQ MCP overview (Microsoft Learn)](https://learn.microsoft.com/en-us/microsoft-agent-365/tooling-servers-overview)
- [Overview of Microsoft Agent 365 (Microsoft Learn)](https://learn.microsoft.com/en-us/microsoft-agent-365/overview)
- [Microsoft Agent 365 service description (Microsoft Learn)](https://learn.microsoft.com/en-us/office365/servicedescriptions/microsoft-agent-365/microsoft-agent-365)
- [Discover AI agents and assess security posture using Microsoft Defender (Microsoft Learn)](https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-inventory)
- [Protect AI agents in real time using Microsoft Defender (Microsoft Learn)](https://learn.microsoft.com/en-us/defender-xdr/security-for-ai/ai-agent-real-time-protection)
