Anyone who built agents over the past year knows the pattern: a department builds itself a helper, it works, nobody knows about it and a year later nobody knows who is responsible either. Microsoft has now delivered tools for this.
Three building blocks
An approval path into the catalogue. Self-built agents can be submitted for review; administrators approve them before they appear in the organisation catalogue. The route from idea to company-wide tool is now governed rather than accidental.
Lifecycle by policy. Agents can be rolled out to groups by policy, and agents without an owner are automatically reassigned. That is exactly what prevents the orphaned helper nobody dares switch off because it is unclear who needs it.
Security requires a licence. Protection functions for agents: discovery, posture assessment, threat detection, have required an appropriately eligible licence since 1 July. Without it, the protections are switched off. Anyone running rules in blocking mode should review them.
Our assessment
This announcement reads as unspectacular and is strategically the most important of the summer. Agents have reached a point where they must be treated like applications: with an owner, approval, inventory and a decommissioning date.
For mid-sized companies this is good news, provided the management is set up before the number of agents grows. Ten agents can be organised retroactively. At fifty it becomes a project.
The point we emphasise: the licence requirement for security functions is not a formality. Overlooking it means running agents without the protections you believe you have.