Darktrace says it is integrating its / SECURE AI product with Microsoft Agent 365, placing Darktrace-generated AI-agent risk signals in the Microsoft 365 Admin Center’s Agent Registry. For security teams already standardizing on Microsoft’s control plane for agents, the practical appeal is straightforward: an agent inventory that can show behavioral-risk context alongside Microsoft’s native identity, data, and threat signals without requiring analysts to begin every investigation in a separate vendor console. The announcement, published by Darktrace on August 4, describes an integration rather than a new enforcement product. Darktrace says its signals will help customers spot anomalous or potentially compromised agents, investigate risk in context, and correlate activity across environments. Microsoft’s own Agent 365 documentation confirms that the platform is designed as a centralized registry and governance layer for agents, with security controls spanning Entra, Purview, and Defender.
What Darktrace has not disclosed is at least as important for administrators planning around the news. There is no stated general-availability date, no list of supported agent frameworks or Microsoft environments, no explanation of which Darktrace / SECURE AI SKU is required, and no description of whether the integration supplies only informational signals or can trigger Microsoft enforcement actions. The announcement is a visibility story, not evidence that Darktrace can block an agent’s activity through Agent 365.

A cybersecurity analyst monitors AI systems, cloud services, and network threats across glowing control-room screens.The integration fills a real gap, but only at the investigation layer​

Microsoft Agent 365 already offers an agent registry, identity controls, policy templates, security posture data, auditability, and Defender-based detection. Microsoft describes the product as a control plane that can inventory agents, show their usage and health, apply governance during onboarding, and surface risks to security teams in the tools they already use.
Darktrace’s stated contribution is behavioral analysis: prompt-related risk identification, anomaly detection across AI agents, cross-environment correlation, and insight into emerging or unknown threats. That division is sensible. Microsoft’s platform is built to establish ownership, manage agent identities, apply access controls, and enforce governance requirements. A behavior-focused supplier can add value by answering a different question: whether an agent that is technically authorized to act is behaving in a way that warrants scrutiny.
That distinction should shape expectations. A registry can tell an administrator that an agent exists, who owns it, what access it has, and whether it meets required policy. It does not automatically establish that an agent’s sequence of actions is normal for its role. An agent with approved access to SharePoint, Exchange, a CRM system, and external tools could still be manipulated through prompt injection, misused through an overly broad delegation path, or quietly move data in a way that looks legitimate when each event is considered alone.
Darktrace argues that its Adaptive AI can supply the behavioral context missing from static policy and inventory views. The claim is plausible as an operational model, but the company has not published the detection logic, data fields, alert fidelity, retention rules, or false-positive rates for this Agent 365 connection. Administrators should therefore treat the launch as an additional signal source to validate, not as a substitute for least privilege, data-loss prevention, logging, or explicit approval controls.

Microsoft has already made Agent 365 the gatekeeper for agent security​

The timing matters because Microsoft has been consolidating AI-agent security around Agent 365. Microsoft’s documentation says Agent 365 became generally available for commercial customers on May 1, 2026, and it is licensed per user. It is available as part of Microsoft 365 E7 or as a standalone product, with Microsoft listing the standalone license at $15 per user per month.
More materially, Microsoft changed the licensing boundary on July 1. Agent-level security capabilities for Copilot Studio and Microsoft Foundry agents that had previously been available through Defender for Cloud Apps or Defender for Cloud now require an Agent 365-eligible license. Microsoft says tenants without such licensing lose access to agent discovery, posture assessment, threat detection, and certain investigation experiences for those services.
That makes Darktrace’s integration potentially useful for organizations that have already accepted Agent 365 as the administrative foundation. But it also means the vendor’s promise of a “single control plane” is not cost-neutral. A company that lacks an eligible Agent 365 license cannot simply add Darktrace signals to preserve the Microsoft agent-security functionality it lost in July.
Microsoft’s transition guidance also shows why a console-level integration needs close operational review. The company moved agent inventory toward a new AgentsInfo data source, deprecated older experiences, changed the handling of legacy real-time protection rules, and required some customers to rebuild blocking policies in the new Security for AI policy experience. Darktrace’s announcement does not say how its data maps into those revised workflows, whether it appears in Advanced Hunting, or whether Darktrace findings can be routed into existing Microsoft Sentinel, Defender XDR, or Security Copilot response processes.
For a SOC, those details determine whether an integration reduces console switching or simply creates a third place to review the same incident.

The missing technical details are the deployment risk​

Darktrace calls itself one of the first security companies to contribute third-party risk signals to the Agent Registry. Microsoft’s public Agent 365 materials confirm that the registry can include Microsoft agents, ecosystem-partner agents, synchronized agents, and self-registered agents. However, Microsoft’s currently published Agent 365 documentation does not identify Darktrace by name or describe the company’s connector, signal schema, onboarding requirements, or support matrix.
That absence does not disprove the integration; Darktrace’s announcement establishes that it has been announced. It does mean IT teams cannot yet independently verify the mechanics behind the marketing language. The initial questions for a proof of concept should be mundane and precise:
  • Does the connector surface signals for Microsoft Copilot Studio and Foundry agents only, or does it also cover agents built with third-party frameworks and agents discovered through registry synchronization?
  • Which Darktrace data is sent into Microsoft 365, and does it include prompt metadata, user identifiers, agent identifiers, tool-call details, sensitive-content classifications, or links back to the Darktrace console?
  • Is the integration read-only, does it create actionable Defender incidents, or can it initiate containment, access revocation, or policy changes?
  • Which licenses are necessary on both sides, and are there tenant, region, cloud, or data-residency restrictions?
  • How are alert ownership, deduplication, retention, and audit trails handled when Microsoft and Darktrace identify the same activity?
These are not implementation footnotes. AI agents frequently blur the line between an application, an identity, and an automation account. A detection that lacks the agent owner, delegated user, accessed data, invoked tool, and exact downstream action may be difficult to prioritize. Conversely, forwarding excessive behavioral telemetry into a central administrative plane can create privacy, data-governance, and retention obligations of its own.

Behavioral signals are useful where policy has already passed​

The strongest part of Darktrace’s argument is that agents can create risk while staying within permissions granted to them. Microsoft makes the same basic case in its Agent 365 security guidance, identifying over-privileged agents, tool misuse, vulnerable or misconfigured agents, prompt injection, data leakage, and agent sprawl as distinct risks.
A conventional access-control decision can establish that an agent was permitted to read a document repository or call an approved business application. It cannot always establish whether an employee’s request, a malicious prompt embedded in a document, or a compromised connector caused the agent to assemble and transmit data in an abnormal way. Detection needs to connect identity, sequence, destination, data type, and historical behavior.
That is where behavioral analytics could become useful, particularly in Windows and Microsoft 365-heavy estates where agents are beginning to operate across Teams, SharePoint, OneDrive, Exchange, business applications, browser-based workflows, and Windows endpoints. The more legitimate systems an agent can reach, the less useful a simple allow-or-deny signal becomes after access is granted.
But the word could is essential. Darktrace has not claimed that its signals will automatically stop agent tool calls, revoke an Entra agent identity, quarantine agent output, or enforce Purview labels. Microsoft continues to own the native governance and enforcement layers through Entra, Purview, and Defender. Darktrace appears to be adding context to the decision-making process surrounding those controls.

What Microsoft 365 administrators should do now​

Organizations already running Agent 365 should treat the Darktrace announcement as a reason to inventory their agent-security workflows before enabling another data source. Confirm that every production agent has a named owner or sponsor, bounded permissions, a documented data-access purpose, and a tested offboarding path. Review whether existing Defender alerts, Advanced Hunting queries, Sentinel playbooks, and incident-response procedures account for agent identities rather than only user and service-principal identities.
Security teams considering the integration should ask Darktrace for a live demonstration using a realistic case: an agent accessing legitimate Microsoft 365 data, then performing an unusual tool invocation, external transfer, or access expansion. The critical test is whether an analyst can see the responsible identity, the agent’s authority chain, the relevant data classification, the behavior deviation, and a clear response action in time to matter.
Darktrace has announced a potentially useful addition to Microsoft’s growing AI-administration stack. The immediate consequence is more limited than the launch language suggests: customers may gain another behavioral-risk lens in the Agent Registry, but they will still need Microsoft’s licensing, native policies, and response controls to turn that visibility into prevention.

References​

  1. Primary source: Darktrace
    Published: 2026-08-04T00:00:00+00:00
  2. Related coverage: learn.microsoft.com
  3. Related coverage: learn.microsoft.com
  4. Related coverage: darktrace.com
  5. Related coverage: developer.microsoft.com
  6. Related coverage: support.microsoft.com
  7. Related coverage: microsoft.github.io
  8. Related coverage: microsoft.com
  9. Related coverage: cdn-dynmedia-1.microsoft.com
  10. Related coverage: adoption.microsoft.com
  11. Related coverage: download.microsoft.com
  12. Related coverage: download.microsoft.com
  13. Related coverage: info.microsoft.com
  14. Related coverage: techradar.com
  15. Related coverage: windowscentral.com
  16. Related coverage: itpro.com
  17. Related coverage: itpro.com
  18. Related coverage: microsoft.com
  19. Related coverage: techcommunity.microsoft.com
  20. Related coverage: microsoftpartners.microsoft.com
  21. Related coverage: techcommunity.microsoft.com
  22. Related coverage: epcgroup.net
  23. Related coverage: licensingschool.co.uk
  24. Related coverage: licensingschool.co.uk
  25. Related coverage: aucotec.com
  26. Related coverage: windowscentral.com
  27. Related coverage: techradar.com
  28. Related coverage: pcgamer.com