@lab.title
This lab teaches you to discover, onboard, govern, and monitor AI agents across your Microsoft 365 tenant. You'll identify Microsoft-built, partner-built, and custom agents using Agent Registry and Agent Map, onboard new agents, and manage agent ownership. You'll then onboard an agent with Agent 365 and reassign ownership. Finally, you'll govern and monitor agents through the Agent 365 control plane, Microsoft 365 admin center, and Microsoft Purview by applying information protection and DLP policies, reviewing audit logs and dashboards, and checking security alerts to ensure compliance and visibility.
Exercises
This lab has the following exercises:
- Exercise 1: Discover and govern agents
- Exercise 2: Secure onboarding & identity governance
- Exercise 3: Protect agent data
- Exercise 4: Monitor agent analytics and usage
Exercise 1: Discover and govern agents
Scenario
As an Agent 365 administrator, you're responsible for maintaining visibility and governance across all agents in the environment. You need to identify which agents exist in the tenant, understand how they're used, and ensure they meet organizational governance requirements. In this exercise you'll use Agent Registry and, Agent Map to discover agents deployed in the tenant, review agent usage, and understand how agents connect to each other and to enterprise resources. By completing this exercise, you'll validate your ability to discover, assess, and govern agents across a Microsoft 365 tenant.
Objectives
At the end of this lab exercise, you'll be able to:
- Use Agent Registry to locate and filter the tenant-wide inventory of agents by publisher, platform, channel, and data source.
- Interpret agent details and usage signals (for example, status, deployment, and last updated) to identify governance and lifecycle follow-up actions.
- Use Agent Map to analyze relationships between agents and connected resources to support risk assessment and governance decisions.
Duration
Estimated time: 20 minutes
Before you start
Before you can start this exercise, you'll need to...
-
[] Sign in to the lab desktop using +++@lab.VirtualMachine(Base23B-W11-22H2).Password+++
-
[] Open a browser and connect to
https://admin.microsoft.com. -
[] Sign in with the admin credentials provided.
Option Value Username @lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).AdministrativeUsernamePassword @lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).AdministrativePassword[!Note] In the pop-up window that says, "You need to set up multifactor authentication," select Skip for now.
-
[] Select the square tile menu option in the upper left corner of the page.
!IMAGEr1e214zm.png
-
[] Select SharePoint. The tenant's SharePoint site should open in another tab or window.
-
[] Confirm that the URL for the SharePoint site begins with https://@lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).TenantPrefix.sharepoint.com/
-
[] Close the SharePoint browser tab and return to the Microsoft 365 Admin Center.
-
[] In the left navigation menu, select Users > Active users
-
[] Select Amber Rodriguez, and then select Reset password.
!IMAGEm2fybagg.png
-
[] Uncheck both boxes and for the password enter
@lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).AdministrativePassword -
[] Select Reset password, and then select Close.
Task 1: Discover agents across the tenant using Agent Registry
-
[] Select Agents on the left-hand side navigation menu.
-
[] Select Overview.
-
[] On the Agent Registry tile, select Explore all agents.
!IMAGE6z1kpohx.png
[!Note] You should be able to review a list of all agents within your organization.
-
[] Review the full agent inventory surfaced in the registry.
[!Note] Next to Filters you'll notice options to filter the Registry view of agents by "Status", "Publisher type", "Channel", "Platform", and "Data source".
-
[] Select Publisher type to filter agents and identify the different types, such as:
- Your org
- Your users
- Microsoft
- Third party
Outcome: You now have a centralized view of all agents deployed or discovered in the tenant using Agent Registry.
Task 2: Analyze agent relationships using Agent Map
-
[] Select Agents on the left-hand side navigation menu.
-
[] Select Overview.
-
[] On the Get early access to Agent 365 tile, select Join the program
!IMAGEhrati3w2.png
-
[] Select All users, and then select Save.
-
[] Select the X in the top right corner to close the flyout page.
-
[] On the Do more with the Frontier program tile, select Try now.
!IMAGEmr1dvs80.png
-
[] On the Terms of Service popup, select I agree.
-
[] Below the Summary on the right side of the page, select Try Now
!IMAGEvc8aerxe.png
-
[] On the You're all set! page, select Go to Admin Home
-
[] Select Agents on the left-hand side navigation menu.
-
[] Select All agents.
-
[] Select Map.
!IMAGEke95ps06.png
[!Note] If you don't see the Map option, refresh the browser page.
-
[] You should see groups of agents, such as:
- External partners
- Microsoft
-
[] Double-click the Microsoft group.
-
[] Zoom in to review the agents within the group.
-
[] Select the Sales agent.
[!Note] A pop-up window should appear with the title Sales. This demonstrates another way to view Agent details via the Agent Map.
Outcome: You now understand how agents interact with one another and with enterprise resources, reinforcing that agents operate as part of a broader ecosystem.
Task 3: Review an agent's metadata
-
[] In the selected Sales agent that you opened in the previous task, review key metadata for the agent. Observe the following tabs, Details, Users, Data & tools, Security, Permissions, Certification, and Activity.
-
[] Select the x on the pop-up window to close it.
Outcome: You're now able to check an agent's metadata.
Task 4: Onboard an Agent
-
[] Select Requests.
!IMAGEx4hy8dn6.png
-
[] Select the IT Helpdesk Agent.
-
[] Select Publish to store.
!IMAGEua8wzgzl.png
-
[] In the Publish agent to selected users page select the following options:
- [] Under Select users or groups who can install the agent, select All users.
- [] Under Select users or groups who will have the agent pre-installed (optional), select All users.
-
[] Select Next.
-
[] On the Apply template page, leave all the defaults, and then select Next.
-
[] On the Review permissions page, select Next.
-
[] On the Review and finish page, select Publish, and then select Done.
-
[] On the All agents page, select Registry
!IMAGE9mibvifb.png
-
[] Select and review the IT Helpdesk Agent.
[!Note] If you do not see the IT Helpdesk Agent, ensure that you clear anything that appears in the search field. !IMAGEw6344rjs.png
-
[] Select the X in the top right corner to close the IT Helpdesk Agent details pane.
Outcome: You have onboarded an agent.
Task 5: Reassign Agent Ownership
-
[] In Edge, open an InPrivate window.
!IMAGEap7fmvnw.png
-
[] In the InPrivate browser go to
https://m365.cloud.microsoft/chat -
[] Sign in as
AdilE@@lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).TenantNamewith the password@lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).UserPassword -
[] On the left-hand navigation panel, select New agent.
[!Note] If you see the Build an agent prompt, select Skip to configure -> !IMAGE6wqnj3fy.png
-
[] Fill out the following fields under the New Agent page:
Field Value Template None Name Contoso AgentDescribe your agent Contoso AgentInstructions Agent to help facilitate documents to the call centerKnowledge
Add specific websiteshttps://@lab.CloudCredential(WWLWWLM365withCopilotA365HydratedStakeholderSteveM).TenantPrefix.sharepoint.com/!IMAGEgftzp2fv.png
-
[] Select Create.
!IMAGEie76fgkw.png
[!Alert] If the agent creation takes more than a few minutes, you may need to refresh the page and start the agent creation over.
-
[] You can close the agent created popup by selecting the X in the upper right corner.
!IMAGEj743k5oe.png
-
[] Close the InPrivate browser window and return to the Microsoft 365 admin center as the MOD Admin.
-
[] Select Agents on the left-hand side of the navigation menu, and then select All agents.
-
[] On the Registry tab, search for the newly created
Contoso Agent. -
[] Select the Contoso Agent.
-
[] Select Assign new owner.
!IMAGEaolfc1jx.png
-
[] In the Search for a user text box, enter and then select
Amber Rodriguez. -
[] Select Assign.
[!Note] You should now see the Owner listed as Amber Rodriguez.
-
[] Select the X in the top right corner to close the agent.
Outcome: You have reassigned ownership of the Contoso Agent.