One caveat first. The public Azure Updates page for item 574204 currently shows "0 Updates found" and doesn't display the entry itself. The feature details below therefore come from Microsoft Learn's "Manage Tools Gateway" admin documentation, which was last updated September 29, 2026, and from Microsoft's own Agent 365 announcements. They do not come from the update listing.
What Microsoft is connecting
The feature is simple to describe. Microsoft's admin documentation says you connect an AI Gateway or APIM instance to the Microsoft 365 admin center. The admin center then discovers the MCP servers registered with that gateway and lets you govern them. After a Global Administrator grants tenant-wide consent, those servers appear on the admin center's Tools page next to the other agent tools.
Microsoft's "What's new in Agent 365 – September 2026" post on Tech Community gave the timing. Beginning September 30, the integration between Microsoft Agent 365 and Azure API Management will begin rolling out, connecting centralized AI governance with policy enforcement at runtime. The same post says AI assets onboarded to Azure API Management, including agents, tools, models, and MCP servers, can be automatically discovered.
That wording is broader than the current admin documentation. The Learn page's FAQ says the admin center discovers only MCP servers registered in the connected gateway, and nothing outside it. Until the documentation says otherwise, plan around MCP servers. Treat "agents, models and tools" as the direction Microsoft has announced, not something you can rely on in the preview today.
Section summary: APIM is where your MCP traffic runs, and the Microsoft 365 admin center is where you govern it. The preview links the two, but it only sees what is registered in the gateway you connect.
Why it matters
Agent sprawl has replaced app sprawl as the headache for many IT teams. Developers create MCP servers quickly, agents call them, and security teams often find out later.
Microsoft's position is that tools should be governed like any other enterprise capability. In a recent Tech Community post on securing intelligent agents, Microsoft said agent tool use should be explicit, least privileged, monitored, and policy governed. The same post describes Agent 365 as helping organizations discover, inventory, govern, and enforce policies across their agent estate, preventing it from becoming an unmanaged shadow application layer.
APIM already handles runtime enforcement. Microsoft Foundry's documentation describes an AI gateway as a single, governed entry point where you can enforce authentication, rate limits, IP restrictions, and audit logging without modifying your MCP servers or agent code. Until now, the gateway and the Microsoft 365 tools inventory were separate. This preview links them, so an allow or block decision made in the admin center applies to servers that run behind APIM.
Agent 365's tools inventory has also grown. Microsoft says Tools management in Agent 365 expands the centralized governance experience beyond MCP servers to include plugins, skills, and connectors, and that feature is now generally available. Administrators can discover connected tools, review key metadata and usage, and apply tenant-wide allow or block controls from one place. Connecting APIM adds gateway-hosted MCP servers to that inventory.
Prerequisites
Check these before you open the admin center. Microsoft's documentation lists four:
- An AI Gateway or APIM instance must already be configured.
- MCP servers must already be registered in that gateway.
- A Global Administrator must be available to grant consent.
- You need access to the Microsoft 365 admin center.
The Global Administrator requirement is the one most likely to slow you down. In tenants that limit standing Global Admin rights through Privileged Identity Management, arrange a role activation in advance.
How to connect APIM
Microsoft documents this sequence:
- Sign in to the Microsoft 365 admin center as a Global Administrator.
- Go to Agents > Settings.
- Select Gateways.
- Under Gateways, turn on the Microsoft Azure toggle to connect an Azure API Management service or Azure AI Gateway.
- Review and accept the requested permissions.
Consent is granted once per tenant and covers every MCP server in the connected gateway. Individual servers don't need separate consent. That saves work, but it also means a server registered in the gateway later is covered by the consent you already gave.
The Gateways page also offers a LiteLLM option, which asks for a gateway name, URL and API key. It's a documented alternative and not part of this APIM preview.
Reviewing and governing discovered servers
Microsoft says discovery starts automatically after consent and usually finishes within a few minutes. Then:
- Go to Agents > Tools in the Microsoft 365 admin center.
- Filter the list by source and select AI gateway.
- Apply governance policies to allow or block each server.
What success looks like: your APIM-registered MCP servers appear in the Tools list under the AI gateway source, and you can set allow or block policies on them.
Tool-level control depends on the APIM tier
You can usually only allow or block a whole server. Microsoft's documentation says per-tool control, meaning blocking or allowing individual tools inside a server, is supported for MCP servers registered in an AI Gateway tier of Azure API Management. Don't expect it on other tiers.
That tier is new. InfoQ reported in August that Microsoft released a dedicated AI Gateway tier of Azure API Management in public preview, with a control plane built around models, MCP servers and tools rather than APIs. So per-tool governance combines two previews, which matters if you're considering production use.
Troubleshooting
- No servers appear after consent. Microsoft's FAQ says to refresh the Tools page and wait longer. Discovery usually takes a few minutes but isn't instant.
- Some servers are missing. Confirm they're registered in the gateway you connected. The admin center can't discover MCP servers outside it.
- The consent step fails or isn't available. Only a user with the Global Administrator role can complete consent.
- A newly added server isn't listed yet. New servers are picked up during later refreshes, so wait for the next refresh cycle.
- You can't block an individual tool. Per-tool control requires the AI Gateway tier of APIM. On other tiers, you can only allow or block whole servers.
The preview caveat
Microsoft's documentation states that preview features are provided under their applicable preview terms and might have limited regional availability or service-level commitments. The Learn page for this feature also says preview features aren't meant for production use and may have restricted functionality. Azure Updates defines "In preview" as available to all Azure customers for non-production use and testing.
My view, as a matter of general practice rather than anything Microsoft documents: test this in a non-production tenant, or at least against a non-production APIM instance, before you rely on it. Check three things:
- Tenant-wide consent covers future servers, so make sure your change-control process accounts for that.
- Blocking a server in the admin center actually stops agents from calling it in your environment.
- If you depend on per-tool controls, the AI Gateway tier's preview status may matter more than this integration's.
There's also a point Microsoft hasn't settled. When InfoQ covered the AI Gateway tier, it noted that architects welcomed the consolidation while questioning where the governance boundary sits. That concern applies here too. You now set policy in the Microsoft 365 admin center, while runtime controls such as rate limits and IP filters stay in APIM. Teams should agree on who owns which layer before an incident forces the question.
Bottom line
This preview isn't a registry of every agent in your organization. It connects the gateway where your MCP servers run to the admin center where Microsoft 365 administrators already manage agent tools.
If you already use APIM for MCP traffic, setup takes four clicks, one Global Admin consent and a few minutes of discovery. If you don't, the setup is a reason to start routing MCP servers through a gateway you control.
For WindowsForum readers: this fits alongside ongoing discussions of Agent 365 tools management, MCP server security, Entra Agent ID and Azure API Management's AI Gateway tier. If you've connected a gateway already, tell us how discovery went in your tenant.
References
- (In preview) Public Preview: Microsoft Agent 365 integration with Azure API Management Azure Updates · 2026-10-08T17:24:34Z
- Azure API Management Adds Dedicated AI Gateway Tier, Governing Models and MCP Tools - InfoQ infoq.com
- Govern MCP Tools by Using an AI Gateway - Microsoft Foundry learn.microsoft.com