Chapter 4 of 6 · Decisions and boundaries

Microsoft Agent 365 secure rollout and data controls

Governed foundation 4.5 hours in a non-production POC

Chapter 4 of 6

Decisions and stop conditions#

The approved change and Purview policy summary must match these coordinates:

CoordinateRequired value
EnvironmentApproved nonproduction environment
AgentOne Agent Registry entry with Available status
Originfoundry, copilot-studio, or agent-builder
PeopleOne approved Entra test group, with a named included member and excluded user
DirectionsHuman-to-agent and agent-to-human
LocationsTeams, OneDrive or SharePoint, and email
ConditionOne approved sensitivity-label ID
ActionRecorded Block or Audit choice
Initial stateTestWithNotifications
Installation stateEnabledAndPropagated after the approved propagation allowance

For an encrypted label, grant the named Agent 365 instance explicit VIEW and EXTRACT rights, then directly share the selected SharePoint or OneDrive source. “All users in the organization” does not grant those rights to the agent.

Choose a labelled destination library, mandatory user labelling, or an approved auto-labelling policy for generated content. Source labels do not automatically protect new Agent 365 content.

Stop before a state change if a license, entitlement, owner, role, permission, coordinate, synthetic source, output-label control, or restore route is missing. Stop if the Purview summary is broader than the approved scope, an encrypted source lacks the required rights, or production data or payload retention enters the path.

For a Foundry agent, do not call Foundry DLP active until both the app-scoped rule and processContent with signed-in user context are in place. Do not assign that Foundry extension to Copilot Studio or Agent Builder.

For a hosted or custom agent, stop if Agent 365 registration is being treated as runtime instrumentation. The source repository must contain the supported Agent 365 observability integration. If the application uses Purview inline checks, it must fail closed or follow the approved fallback when the policy service does not return a usable decision.

Field reference#

Complete every __REQUIRED_*__ value in agent-deployment.json. Before the DLP change, set dlpGate.policyState to ReadyForSimulation and dlpGate.propagationState to NotStarted. After the Purview operator enables the policy and the delivery owner inspects the recorded propagation allowance, set them to EnabledAndPropagated and Confirmed. Those values record installation authorization. Purview and the approved change record remain authoritative.

The scripts reject every unresolved sentinel. They also reject an installation request unless the contract contains the post-propagation values above.

Session 05

Microsoft Agent 365 secure rollout and data controls slide deck