Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
161 changes: 161 additions & 0 deletions case-studies/governing-ai-agents-with-microsoft-agent-365.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,161 @@
<!DOCTYPE html>
<html lang="en">

<head>
<meta charset="UTF-8" />
<meta content="width=device-width,initial-scale=1.0,maximum-scale=1.0" name="viewport">

<!-- SEO -->
<meta name="description" content="See how a global retail organization governed AI agents at scale with Microsoft Agent 365 — managing agent identities, enforcing data boundaries, and achieving audit readiness.">

<!-- Open Graph -->
<meta property="og:title" content="Governing AI agents at enterprise scale with Microsoft Agent 365 | MAQ Software" />
<meta property="og:type" content="website" />
<meta property="og:image" content="https://maqsoftware.com/images-new/case-studies/governing-ai-agents-with-microsoft-agent-365.webp" />
<meta property="og:description" content="See how a global retail organization moved from ungoverned, shadow AI agents to a secure, audit-ready foundation with Microsoft Agent 365." />

<!-- Twitter Theme -->
<meta name="twitter:widgets:theme" content="light">

<!-- Title &amp; Favicon -->
<title>Governing AI agents at enterprise scale with Microsoft Agent 365 | MAQ Software</title>
<link rel="shortcut icon" type="image/x-icon" href="/images/logos/MAQ-Software-URL.png">

<!-- Fonts -->
<link href="https://fonts.googleapis.com/css?family=Roboto:300,400,500,700%7CHind+Madurai:400,500&amp;subset=latin-ext" rel="stylesheet">
<link href="https://fonts.googleapis.com/css2?family=Inter&display=swap" rel="stylesheet">

<!-- CSS -->
<link rel="stylesheet" href="/css/core.min.css" />
<link rel="stylesheet" href="/css/skin.css" />
<link rel="stylesheet" href="/css/styles.css" />

<!--[if lt IE 9]>
<script type="text/javascript" src="http://html5shiv.googlecode.com/svn/trunk/html5.js"></script>
<![endif]-->
<!-- Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-S0W302CGQG"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', 'G-S0W302CGQG');
</script>
<script type="text/javascript">
(function(c,l,a,r,i,t,y){
c[a]=c[a]||function(){(c[a].q=c[a].q||[]).push(arguments)};
t=l.createElement(r);t.async=1;t.src="https://www.clarity.ms/tag/"+i;
y=l.getElementsByTagName(r)[0];y.parentNode.insertBefore(t,y);
})(window, document, "clarity", "script", "oekduyvjws");
</script>
</head>

<body class="shop blog">

<!-- Header -->
<header id="header" class="header header-absolute header-fixed-on-mobile header-transparent"
data-bkg-threshold="100" data-sticky-threshold="0"></header>
<!-- Header End -->
<div class="section-block bkg-grey-ultralight"></div>

<!-- Content -->
<div class="content clearfix best-practices-text">
<div class="section-block clearfix pt-0 pb-0 bkg-grey-ultralight">
<div class="row">
<!-- Content Inner -->
<div class="column width-10 offset-1 content-inner blog-single-post bkg-grey-ultralight">
<article class="post">
<div class="post-content with-background">

<h1 class="post-title center" style="font-size: 1.75rem;">Governing AI agents at enterprise scale with Microsoft Agent 365</h1>
<h3 class="post-title center">How a global retail organization secured and scaled its AI agents</h3>

<div class="center">
<img src="/images-new/case-studies/governing-ai-agents-with-microsoft-agent-365.webp"
alt="Hands typing on a laptop with AI governance and analytics dashboard graphics"
style="width:100%; max-width:800px; border-radius:8px;">
</div>

<div style="background:#ffffff; border:1px solid #e5e5e5; border-radius:8px; padding:1.5rem 2rem; margin:2rem 0;">
<ul class="list-unstyled" style="margin:0;">
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Client:</strong> Global retail organization</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Industry:</strong> Retail</li>
<li class="text-large" style="margin-bottom:0;"><strong>Technology:</strong> Microsoft Agent 365, Microsoft Entra, Microsoft Purview, Microsoft Defender for Cloud</li>
</ul>
</div>

<h2>About our client</h2>
<p class="text-large">Our client is a global retail organization with operations across multiple geographies, managing a large Microsoft 365 environment. Their Global Business Services (GBS) team — responsible for internal IT, admin operations, and compliance — had been rapidly expanding their use of AI agents across departments to automate workflows, handle internal requests, and support day-to-day operations. With increased adoption, bigger challenges came into picture.</p>

<h2>The issue at hand</h2>
<p class="text-large">As AI agent adoption accelerated across the GBS team, governance could not keep pace. The organization faced:</p>
<ul>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>No centralized agent inventory:</strong> The IT team had no reliable way to track how many agents were active in their tenant, who owned them, or what systems they could access.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Ungoverned agent identities:</strong> Agents had been provisioned without formal identity management, resulting in over-permissioned access to sensitive internal systems and HR data.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Compliance and audit exposure:</strong> With no audit trail of agent actions, the compliance team could not respond confidently to internal reviews or demonstrate regulatory readiness.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Shadow AI proliferation:</strong> Business teams were building and deploying agents outside formal IT processes, creating security blind spots across the environment.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>No runtime threat detection:</strong> There was no mechanism to detect or respond to risky agent behavior in real time, leaving the organization exposed to potential data misuse.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>No unified visibility:</strong> Security, IT, and compliance teams were working from disconnected views of the agent landscape — with no single source of truth across agent activity, access, and behavior.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Reactive incident management:</strong> Without proactive monitoring, the team only became aware of agent-related issues after the fact, making it difficult to contain risk before damage occurred.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Disconnected DevOps and AI workflows:</strong> Agent development and deployment pipelines were operating independently of IT governance and security processes, creating gaps between how agents were built and how they were controlled in production.</li>
</ul>

<h2>Our approach</h2>
<p class="text-large">The GBS IT and compliance teams were engaged through a structured delivery aligned to our Microsoft Agent 365 governance methodology. The engagement started with a discovery and assessment phase to map the full agent landscape, identify governance gaps, and establish a baseline. This was followed by deployment of governance controls across Microsoft Agent 365, Microsoft Entra, Microsoft Purview, and Microsoft Defender for Cloud — directly in the client's tenant. The final stage focused on validation, stakeholder enablement, and handover to ensure the governance model could be operated independently from day one.</p>

<h2>Implementation process</h2>
<p class="text-large">The engagement began with a thorough discovery of the client's existing agent landscape. A full inventory of all AI agents active across the Microsoft 365 tenant was conducted — including Copilot agents, custom bots, and third-party integrations. The existing identity and access management posture for non-human identities was reviewed, data boundary controls were assessed, and findings were mapped against zero trust principles to deliver a prioritized governance roadmap.</p>
<p class="text-large">With a baseline established, the tenant was onboarded into Microsoft Agent 365 and agent identities were provisioned in Microsoft Entra with scoped, least-privilege access policies. Key controls deployed included:</p>
<ul>
<li class="text-large" style="margin-bottom:0.5rem;">Audit logging and activity monitoring across all agent interactions.</li>
<li class="text-large" style="margin-bottom:0.5rem;">Microsoft Purview DLP policies scoped to AI workloads to enforce data boundaries.</li>
<li class="text-large" style="margin-bottom:0.5rem;">Microsoft Defender for AI enabled real-time threat detection and risky behavior alerting.</li>
<li class="text-large" style="margin-bottom:0.5rem;">Zero Trust access controls across agent-to-user, agent-to-data, and agent-to-agent interactions.</li>
</ul>
<p class="text-large">Agent deployment pipelines were integrated with the Agent 365 control plane, ensuring agents built by the GBS team entered the governance framework from the point of deployment. End-to-end validation was conducted, enablement sessions were delivered with SecOps and compliance teams, and full documentation was handed over at close of engagement.</p>

<h2>Business impact</h2>
<p class="text-large">The implementation delivered measurable improvements across security, compliance, and operational efficiency for the GBS team:</p>
<ul>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Full agent visibility achieved:</strong> A complete, centralized inventory of all agents operating across the tenant was established for the first time — eliminating blind spots and giving leadership a clear picture of their agent footprint.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Reduced security exposure:</strong> Over-permissioned agent identities were remediated, with all agents provisioned under scoped, auditable access policies aligned to least-privilege principles.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Audit-ready in weeks:</strong> Agent activity logs and access records were demonstrated within the engagement timeline, significantly reducing audit preparation time.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Shadow AI brought under control:</strong> Agents created outside formal IT processes were identified and brought into the governance framework, eliminating unmanaged blind spots across the environment.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Proactive incident response:</strong> With Defender for AI monitoring in place, the SecOps team moved from reactive to proactive — able to detect and respond to risky agent behavior in real time before damage could occur.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Connected DevOps and governance:</strong> Agent deployment pipelines were integrated with the governance control plane, ensuring every new agent entered the environment governed from day one.</li>
<li class="text-large" style="margin-bottom:0.5rem;"><strong>Operational confidence:</strong> SecOps and compliance teams were equipped with documented configurations and a governance model fully operatable independently from day one.</li>
</ul>

<h2>Conclusion</h2>
<p class="text-large">By implementing Microsoft Agent 365, the retail organization's GBS team transformed their approach to AI agent governance — moving from an ungoverned, fragmented landscape to a secure, audit-ready foundation. With agent identities managed, data boundaries enforced, runtime monitoring in place, and DevOps workflows connected to governance, the organization can now scale agentic AI with confidence across their enterprise.</p>
<p class="text-large">To learn how we can help your organization govern and scale AI agents with Microsoft Agent 365, contact our team at <a href="mailto:CustomerSuccess@MAQSoftware.com">CustomerSuccess@MAQSoftware.com</a>.</p>

<div class="section-block pt-10 pb-10 bkg-white"></div>
<div class="post-info center">
<span class="post-date">Published: June 10, 2026</span>
</div>

</div>
</article>
</div>
</div>
</div>
<div class="section-block bkg-grey-ultralight"></div>
</div>
<!-- Content End -->

<!-- Footer -->
<footer id="footer" class="footer footer-light bkg-grey-ultralight"></footer>
<!-- Footer End -->

<!-- Js -->
<script src="https://code.jquery.com/jquery-3.6.0.min.js"></script>

Check warning

Code scanning / CodeQL

Inclusion of functionality from an untrusted source Medium

Script loaded from content delivery network with no integrity check.
<script src="https://maps.googleapis.com/maps/api/js?key=AIzaSyC3JCAhNj6tVAO_LSb8M-AzMlidiT-RPAs"></script>
<script src="/js/timber.master.min.js"></script>
<script src="../js/sidenav.js"></script>
<script>
$("#footer").load("/footer.html");
</script>
</body>

</html>
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
18 changes: 9 additions & 9 deletions services/artificial-intelligence-and-machine-learning.html
Original file line number Diff line number Diff line change
Expand Up @@ -158,8 +158,8 @@ <h1 class="section-header">Our agentic AI and machine learning capabilities</h1>
imageAlt: "Dashboard for governing and monitoring AI agents",
sectionTitle: "Govern your AI agents with Microsoft Agent 365",
bodyText: "Secure and scale your AI agents with confidence. We help you deploy Microsoft Agent 365 to govern agent identities, enforce access policies, monitor behavior, and maintain audit-ready logs — ensuring every agent in your environment operates within enterprise-grade controls.",
linkHref: "/case-studies.html?filter=gen-ai-and-machine-learning",
linkText: "Agentic AI & machine learning case studies"
linkHref: "/case-studies/governing-ai-agents-with-microsoft-agent-365",
linkText: "Read the Agent 365 case study"
},
{
title: "Agentic DevOps",
Expand Down Expand Up @@ -258,6 +258,13 @@ <h1 class="section-header">Related case studies</h1>

<script>
const caseStudyCards = [
{
href: "/case-studies/governing-ai-agents-with-microsoft-agent-365.html",
imageSrc: "../images-new/case-studies/governing-ai-agents-with-microsoft-agent-365.webp",
imageAlt: "Hands typing on a laptop with AI governance and analytics dashboard graphics",
title: "Governing AI agents at enterprise scale with Microsoft Agent 365",
bodyText: ""
},
{
href: "https://blog.maqsoftware.com/2025/11/modernizing-software-development.html",
imageSrc: "../images-new/case-studies/modernizing-the-software-development-lifecycle-with-github-copilot.jpg",
Expand All @@ -279,13 +286,6 @@ <h1 class="section-header">Related case studies</h1>
title: "Reshaping industries with agentic AI solutions",
bodyText: ""
},
{
href: "https://blog.maqsoftware.com/2025/03/empowering-self-service-using-custom.html",
imageSrc: "../images-new/case-studies/empowering-self-service-using-custom-copilot-agent-with-power-bi-embedded.jpeg",
imageAlt: "Woman working on a laptop computer with Copilot open",
title: "Empowering self-service using Custom Copilot agent with Power BI Embedded",
bodyText: ""
}
];
// The final digit represents the number of cards per row
renderImageCards("#caseStudySection", caseStudyCards, 4);
Expand Down