Microsoft moved the Foundry agent security capabilities from Defender for Cloud into its Agent 365 license, effective July 1, 2026. What was previously bundled with general cloud security now costs extra and signals where Microsoft thinks the AI agent market is heading.

What is changing

Up until now, organizations running AI agents in Microsoft Foundry environments could rely on security capabilities bundled into Defender for Cloud. Those capabilities – threat detection for agent behavior, compliance monitoring across agent workflows, and secure deployment guardrails – are all moving to a dedicated licensing model under Agent 365.

Microsoft Agent 365 launched in May 2026 as a standalone product priced at $15 per user per month, or bundled into the Microsoft 365 E7 SKU at $99 per user per month. The transition of Foundry agent security into this licensing structure means that if you are running AI agents on Azure, you now need Agent 365 to get the same security coverage you previously had through Defender for Cloud.

What this covers

Agent protection under Agent 365 includes:

These are the same capabilities that existed in Defender for Cloud for Foundry agents. The key change is the licensing model, not the feature set.

Why this matters

This transition tells you something about where Microsoft sees the AI agent market going. Bundling agent security into a general-purpose cloud security product made sense when agents were experimental. Carving it out as a dedicated license signals that Microsoft expects broad, enterprise-scale agent deployment. They are betting that organizations will need a dedicated governance layer for agents, separate from general cloud workload protection.

Defender for Cloud is often included in enterprise agreements or bundled with Azure subscriptions. Agent 365 is a separate line item. For organizations running dozens or hundreds of Foundry agents, the licensing cost adds up. $15 per user per month for the standalone SKU is not outrageous compared to other security add-ons, but it is an additional line item that needs approval.

For teams managing AI agents on Azure, the immediate action is to audit which Foundry agents are currently protected under Defender for Cloud and plan the transition. Microsoft has said the capabilities remain available through the transition period, but long term, Agent 365 is the path forward for agent security coverage.

How this compares to the market

Microsoft is not the only player moving toward dedicated AI agent security products. A number of third-party providers have emerged offering agent monitoring and governance. Companies like Robust Intelligence and HiddenLayer offer runtime protection for AI models, while cloud-native security products like Wiz and Orca have started adding agent-specific detections.

What sets Microsoft’s approach apart is the direct integration with Foundry. Agent 365 is not a bolt-on – it hooks into the same agent runtime, activity logs, and deployment pipelines that Foundry uses. That means lower latency for detection, better context for alerts, and less configuration overhead compared to stitching together a third-party solution.

The tradeoff is lock-in. Once you are on Agent 365, moving agents to another platform means rebuilding your security posture from scratch. Organizations running agents across multiple clouds may prefer a platform-agnostic solution even if it means more work upfront.

What this means for developers

If you are building AI agents on Microsoft Foundry, the practical impact depends on how your organization handles licensing. If a central security team manages Microsoft 365 licensing, they should already be looking at Agent 365. If you are an individual developer or a small team, you may need to budget for the additional license.

The security capabilities themselves are worth having. AI agents have a unique risk profile: they can act autonomously, access multiple systems, and make decisions that affect production data. The threat detection and compliance monitoring that Agent 365 provides is not just a compliance checkbox. It addresses real attack vectors that are specific to autonomous agent architecture.

One area to watch is whether Microsoft expands Agent 365 beyond Foundry to cover agents running on other platforms. The licensing model seems designed for portability, and Microsoft has hinted at broader integrations in their May 2026 launch announcements. If that happens, Agent 365 could become the default security layer for enterprise AI agents regardless of where they run.

For now, the practical advice is straightforward. If you are using Foundry agents in production, work with your security team to assess whether Agent 365 coverage is needed and budget for the transition. If you are still evaluating Foundry and have not deployed agents yet, factor Agent 365 into your cost projections from the start. And if you are running agents on a different platform entirely, watch what Microsoft does next – the competitive pressure will likely push AWS and Google Cloud to offer similar dedicated agent security products before long.

Leave a Reply

Your email address will not be published. Required fields are marked *