Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.
Amazon Bedrock AgentCore vs Microsoft Agent 365
Amazon Bedrock AgentCore
AWS platform for building, deploying, and operating AI agents
Microsoft Agent 365
Microsoft 365 control plane to discover, manage, govern, and secure AI agents
Short answer
Amazon Bedrock AgentCore is AWS’s platform to build, deploy, and operate agents, while Microsoft Agent 365 is a Microsoft 365 control plane for agents built and run elsewhere.Source 1, Source 2, Source 3, Source 4 AgentCore is billed by use of each service; Agent 365 is licensed per user, with agent identities in Microsoft Entra.Source 5, Source 6, Source 7
Where each one sits
Six layers of running AI agents at a company, and what each product’s own public sources say it covers.
These aren’t the same kind of product
Amazon Bedrock AgentCore
Microsoft Agent 365
- Agents across organizations: Not publicly documented
At a glance
What each one is
Amazon Bedrock AgentCore
Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.Source 1 Its modular services, usable together or independently, include Runtime to host agents, Identity, Gateway and Policy to control tool access, Observability, and AWS Agent Registry.Source 1, Source 8, Source 9, Source 10, Source 23
Microsoft Agent 365
Microsoft Agent 365 is a Microsoft 365 service that provides a centralized control plane to discover, manage, govern, and secure AI agents.Source 2 Microsoft splits the work: Agent 365 inventories agents, and Microsoft Entra Agent ID handles identities, permissions, and protections.Source 24
The differences that matter
How far each registry reaches
Amazon Bedrock AgentCoreAWS Agent Registry can list agents and MCP servers on AWS, on premises, or in other clouds; it currently auto-detects only AgentCore Runtimes and Gateways.Source 1, Source 11
Microsoft Agent 365The Agent 365 registry covers Microsoft and non-Microsoft agents; agents built outside Microsoft 365 channels and Entra Agent ID need extra steps to appear.Source 12, Source 20, Source 25
AI agents can search AWS Agent Registry through its MCP endpoint.Source 8 Whether agents can search the Agent 365 registry is not publicly documented.
Where policy is enforced
Amazon Bedrock AgentCorePolicy can check each request through an AgentCore Gateway against rules, written in natural language or Cedar, before allowing tool access.Source 10
Remote and partner agents
Amazon Bedrock AgentCoreA registry can be shared with AWS accounts outside your AWS Organization by invitation, and resource-based policies can open a Runtime agent to another account.Source 16, Source 28
Microsoft Agent 365A published agent can be added to a customer’s tenant through a multitenant blueprint; managing agents across tenants you administer is in preview.Source 7, Source 29
Microsoft says its separate Copilot Studio and Microsoft Foundry can provide built-in Agent 365 integration for some scenarios; their agents can call A2A agents hosted elsewhere.Source 30, Source 31, Source 32, Source 33
For security teams
What a security review asks, answered from each vendor’s public documentation.
Full comparison
18 criteria in five groups. Every cell links to its source, or says no public source answers it.
| Amazon Bedrock AgentCore | Microsoft Agent 365 | |
|---|---|---|
| What it is | ||
| What it is and who it’s for | AWS platform to build, deploy, and operate agents with any framework and foundation model, as modular services used together or independently.Source 1 | Microsoft 365 service providing a centralized control plane to discover, manage, govern, and secure AI agents, aimed at IT and security leaders.Source 2, Source 25 |
| Maturity | Generally available since October 2025; AWS Agent Registry since August 2026.Source 21 Support for the Registry’s preview namespace ends on 30 October 2026.Source 11 | Generally available since 1 May 2026 for the Commercial segment.Source 22 Registry sync and multi-tenant management are in preview.Source 29, Source 30 |
| Control | ||
| Agent registry and discovery | AWS Agent Registry catalogs agents, MCP servers, tools, and skills on AWS, on premises, or in other clouds, behind an approval workflow.Source 1, Source 8 | An agent registry in the Microsoft 365 admin center lists Microsoft and non-Microsoft agents, including agents without an Entra agent identity.Source 12, Source 20 |
| Identity and access control | Agent identities are workload identities in AgentCore Identity.Source 9 Calls to Runtime agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.Source 19, Source 40 | Agent identities live in Microsoft Entra Agent ID, managed with Conditional Access, permission grants, and consent.Source 7 The inventory also lists agents without one.Source 20 |
| Ownership, policy, and revocation | Policy can check Gateway traffic against rules on which tools agents may call, in natural language or Cedar.Source 10 An owner field is not publicly documented. | Each Entra agent identity needs a sponsor.Source 7 Admins can block agents organization-wide, apply policy templates, and review agents without owners.Source 12, Source 26, Source 27 |
| Audit log and observability | CloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.Source 11, Source 36, Source 37 Telemetry is OpenTelemetry-compatible, in CloudWatch.Source 23 | Purview audit logs and eDiscovery of agent activities need E7 or Agent 365; not in GCC.Source 2 Observability data appears in Defender and Purview, kept 30 days.Source 3, Source 13 |
| Connection | ||
| How agents connect | Agents can deploy to serverless AgentCore Runtime, or a Gateway can forward requests to an agent’s endpoint URL.Source 1, Source 15 | The SDK works with agents on Azure, AWS, Google Cloud, or on premises.Source 3 Notifications, in preview, need a messaging endpoint URL that Agent 365 sends to.Source 35 |
| Agents across organizations | AWS RAM shares a registry with AWS accounts, by invitation outside your AWS Organization.Source 16 Resource-based policies can open a Runtime agent to another account.Source 28 | A published agent can join a customer’s tenant through a multitenant blueprint.Source 7 Agents in Microsoft’s separate Foundry and Copilot Studio can call A2A agents.Source 32, Source 33 |
| Protocol support | Runtime agents can serve HTTP, MCP, A2A, or AG-UI.Source 41 Gateway acts as one MCP server over its MCP targets; Registry checks records against MCP and A2A schemas.Source 11, Source 42 | Tenant-wide control of agents’ tools, including Microsoft MCP servers; your own in preview.Source 2, Source 17 Microsoft’s separate Foundry and Copilot Studio agents can use A2A.Source 32, Source 33 |
| Frameworks, models, and clouds supported | Runtime takes custom or open-source frameworks, such as CrewAI, LangGraph, and Strands Agents.Source 1 Registry and Identity work with agents outside Runtime.Source 14, Source 18 | Works with Microsoft and third-party agents.Source 2 SDK docs name LangChain, CrewAI, LlamaIndex, and the OpenAI Agents SDK; agents keep their own host.Source 4, Source 30 |
| Operations | ||
| Deployment options and data residency | AWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.Source 1, Source 43 | A Microsoft 365 service that honors the EU Data Boundary and doesn’t currently support Advanced Data Residency.Source 2, Source 13 Self-hosting it is not publicly documented. |
| Compliance attestations | AWS lists AgentCore as FedRAMP (Class C and Class D) compliant.Source 38, Source 39 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.Source 21, Source 38 | Microsoft says Agent 365 meets all FedRAMP High controls its assessor reviewed, with authorization pending (announced).Source 2 Not yet a Core Online Service.Source 13 |
| Support and SLA | AWS says the Amazon Bedrock SLA applies to AgentCore.Source 14 Basic Support is included for all AWS customers.Source 44 | No specific SLA for the Frontier preview program.Source 45 An SLA or support plan specific to the generally available service is not publicly documented. |
| Time and effort to get running | An AWS account with credentials, plus IAM permissions for AgentCore calls and CDK deployment.Source 46 The AgentCore CLI is an npm package needing Node.js 20 or later.Source 46 | Enterprise customers need Microsoft 365 E5, or E3 with Defender Suite and Purview Suite, and at least one user with an Agent 365 license.Source 6, Source 22 |
| Pricing model and public prices | By use, billed per service, with no upfront commitment or minimum fee.Source 5 Registry has a monthly free tier; Runtime v1 CPU is $0.0895 per vCPU-hour.Source 5 | Per user, not per agent: lists at $15 a month standalone, or in Microsoft 365 E7.Source 6 Microsoft Cloud subscribers get foundational capabilities at no extra cost.Source 6 |
| Building | ||
| Agent building tools | Harness defines an agent from a model, system prompt, and tools in one API call, or you write the loop with Strands, LangGraph, Google ADK, or others.Source 1, Source 46 | Microsoft says the Agent 365 SDK isn’t an agent-building framework.Source 3 For low-code building, its docs point to Microsoft’s separate Copilot Studio.Source 47 |
| Model access | Model-agnostic: AWS names OpenAI, Google Gemini, Anthropic Claude, Amazon Nova, Meta Llama, and Mistral models, in or outside Amazon Bedrock.Source 14 | Microsoft says the SDK doesn’t call or select models; the agent keeps making its own model calls.Source 3, Source 4 |
| Integrations and ecosystem | Gateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import partner tools bought through AWS Marketplace.Source 14, Source 48 | Microsoft says it launched with partner agents and agent factories, such as Zendesk and n8n.Source 49, Source 50 Work IQ MCP tools for Mail, Teams, and more are in preview.Source 51 |
Which to choose
Choose Amazon Bedrock AgentCore if
- You want to build, deploy, and operate agents on one AWS platform, with frameworks such as LangGraph, CrewAI, or Strands Agents.Source 1
- You want per-request policy at a gateway, written in natural language or Cedar, on which tools each agent may call.Source 10
- You want pay-per-use pricing for each service, with no upfront commitment or minimum fee.Source 5
- Your company uses AWS Organizations and wants one shared registry, with AgentCore Runtimes and Gateways in member accounts auto-detected once enabled.Source 11, Source 16
Choose Microsoft Agent 365 if
- You build agents in Microsoft’s separate Copilot Studio or Foundry, which Microsoft says can provide built-in Agent 365 integration for some scenarios.Source 30, Source 31
- You want agent identities in Microsoft Entra, under the same Conditional Access, consent, and lifecycle controls as the rest of your tenant.Source 7
- You want named accountability: each Entra agent identity needs a sponsor, and admins can block or delete agents without owners.Source 7, Source 12
- You’d rather license per user than per agent: one Agent 365 license covers all of a user’s agents.Source 6
Questions buyers ask
Can Microsoft Agent 365 manage agents on Amazon Bedrock AgentCore?
How is each one priced?
Do they support MCP and A2A?
AgentCore Runtime can host MCP and A2A servers.Source 41 Agent 365 can control agents’ tool access, including Microsoft MCP servers; registering your own is in preview.Source 2, Source 17 Microsoft documents A2A for its separate Foundry and Copilot Studio.Source 32, Source 33 For Agent 365 itself, A2A is not publicly documented.
Does AgentCore work with Microsoft Entra ID?
How we compare
Read the full methodEvery claim on this page links to a public source. Where none answers a question, the page says so.
We re-check every fact at least every 90 days. This page was last checked .
Something wrong or out of date? Tell us and we’ll correct it.
Sources
60 public sources, each with the date we checked it. Every one opens in a new tab.
Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) Back:abcdefghijklmnop
Source 2: Microsoft Agent 365 - Service Descriptions | Microsoft Learn Back:abcdefghijkl
Source 3: Agent 365 SDK frequently asked questions | Microsoft Learn Back:abcdefgh
Source 4: Microsoft Agent 365 SDK overview | Microsoft Learn Back:abcdefg
Source 7: Agent 365 identity | Microsoft Learn Back:abcdefghijklmn
Source 8: AWS Agent Registry: Discover and manage agents, tools, and resources Back:abcde
Source 9: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity Back:abcdef
Source 10: Policy in Amazon Bedrock AgentCore: Control Agent Interactions Back:abcdef
Source 11: Key capabilities - AWS Agent Registry Back:abcdefg
Source 12: Agent Registry in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abcdef
Source 13: Data handling, data residency, and compliance in Agent 365 observability | Microsoft Learn Back:abcdef
Source 15: HTTP passthrough targets - AgentCore Gateway Back:abc
Source 16: Sharing a registry across accounts with AWS RAM Back:abcde
Source 17: Bring your own (BYO) MCP server in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abc
Source 20: Agent Registry convergence with Microsoft Agent 365 | Microsoft Learn Back:abcde
Source 21: Release notes - Amazon Bedrock AgentCore Back:abc
Source 22: Microsoft Agent 365 overview | Microsoft Learn Back:abc
Source 23: Observe your agent applications on Amazon Bedrock AgentCore Observability Back:ab
Source 24: Protect agent identities with Microsoft Entra | Microsoft Learn Back to text
Source 25: Microsoft Agent 365: The Control Plane for Agents Back:ab
Source 27: Governance and Lifecycle actions for agents available in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:abc
Source 28: Resource-based policies for Amazon Bedrock AgentCore Back:abc
Source 29: Manage agents across multiple tenants in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Back:ab
Source 30: Choose an Agent 365 Integration Option | Microsoft Learn Back:abcde
Source 31: What is Microsoft Foundry? - Microsoft Foundry | Microsoft Learn Back:ab
Source 32: Connect to an agent over the Agent2Agent (A2A) protocol - Microsoft Copilot Studio | Microsoft Learn Back:abcd
Source 33: Connect to an A2A agent endpoint from Foundry Agent Service - Microsoft Foundry | Microsoft Learn Back:abcd
Source 34: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore Back to text
Source 35: Agent Messaging Endpoint | Microsoft Learn Back:ab
Source 36: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail Back:ab
Source 37: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore Back:ab
Source 38: Compliance validation for Amazon Bedrock AgentCore Back:abc
Source 39: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services Back:ab
Source 40: Authenticate and authorize with Inbound Auth and Outbound Auth Back to text
Source 41: Understand the AgentCore Runtime service contract Back:ab
Source 42: Supported targets for Amazon Bedrock AgentCore gateways Back to text
Source 43: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations Back to text
Source 45: Preview Agent 365 features through the Frontier program | Microsoft Learn Back to text
Source 46: Get started with Amazon Bedrock AgentCore Back:abc
Source 47: Get started with Microsoft Agent 365 | Microsoft Learn Back to text
Source 48: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models Back to text
Source 49: Ecosystem partner agents available in Agent 365 | Microsoft Learn Back to text
Source 50: Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog Back to text
Source 51: Connect existing agents to Microsoft Agent 365 | Microsoft Learn Back to text
Source 52: Connect Amazon Bedrock to Microsoft Agent 365 | Microsoft Learn Back:abcd
Source 53: Connected platforms in Microsoft Agent 365 | Microsoft Learn Back to text