Chapter 3 of 6 · Before you start

Microsoft Agent 365 secure rollout and data controls

Governed foundation 4.5 hours in a non-production POC

Chapter 3 of 6

Confirm the following before opening the portals:

  • A supported nonproduction agent appears in Agent Registry with Available status and supports group installation. The source-platform owner confirms its publication, runtime owner, and approved lifecycle path. The runtime owner is named. (See Governed agent baseline guide for a Foundry agent.)
  • The Microsoft 365 administrator can open Agents > All agents > Registry, find the agent with Available status, inspect group installation, and remove that scoped installation.
  • The delivery owner approved the nonproduction group, host product, use case, labelled synthetic item, label and encryption rights, DLP action and locations, notification and incident route, output-label control, and restore route.
  • The DLP and label operator has Compliance Data Administrator in the approved tenant. The audit operator has View-Only Audit Logs in Microsoft Purview and Exchange admin center.
  • The Microsoft Graph Audit Search application has AuditLogsQuery.Read.All application permission with administrator consent.
  • The Purview operator, Agent 365 owner, information protection owner, source-platform owner, data owner, and audit owner accept the responsibilities in coverage-handoff.md. For Foundry, include the Foundry platform owner and application developer.
  • For a hosted or custom agent, the runtime owner identifies the supported Python or .NET Agent 365 integration, token flow, required telemetry attributes, and the application path that acts on a Purview policy result.

Implementation files#

TypeFileConsumer
Deploymentartifacts/agent-deployment.jsonThe Microsoft 365 administrator and Session 05 preflight scripts
Recordartifacts/governance/coverage-handoff.mdThe data, information protection, Agent 365, source-platform, and audit owners
Runtimeartifacts/operations/agent-activity-audit-query.jsonThe Agent 365 audit-query scripts

Keep tenant IDs, group object IDs, user identities, permission-consent records, policy summaries, findings, prompts, responses, audit exports, and portal-state copies in approved customer systems.

Session 05

Microsoft Agent 365 secure rollout and data controls slide deck