Skip to content

Blocks.ai publishes this comparison and sells in this market. Every claim about another product links to a public source.

Amazon Bedrock AgentCore vs Microsoft Agent 365

Amazon Bedrock AgentCore

AWS platform for building, deploying, and operating AI agents

Microsoft Agent 365

Microsoft 365 control plane to discover, manage, govern, and secure AI agents

Short answer

Amazon Bedrock AgentCore is AWS’s platform to build, deploy, and operate agents, while Microsoft Agent 365 is a Microsoft 365 control plane for agents built and run elsewhere.⁠Source 1, Source 2, Source 3, Source 4 AgentCore is billed by use of each service; Agent 365 is licensed per user, with agent identities in Microsoft Entra.⁠Source 5, Source 6, Source 7

Where each one sits

Six layers of running AI agents at a company, and what each product’s own public sources say it covers.

These aren’t the same kind of product

Where they overlap
Both keep a registry of agents, give agents their own identities, control which tools agents can use, and record activity.⁠Source 2, Source 7, Source 8, Source 9, Source 10, Source 11, Source 12, Source 13
Where they differ
With AgentCore, teams can also build agents and host them, with Harness and serverless Runtime; the Agent 365 SDK doesn’t build, host, or execute agents, or select models.⁠Source 1, Source 4
Running both
Microsoft says the Agent 365 SDK works with agents hosted on AWS; AWS says AgentCore Identity’s authorizer can use Microsoft Entra ID.⁠Source 3, Source 14
Public sources · checked 2 October 2026
  • Offered
  • Preview
  • Not included
  • Not publicly documented

Amazon Bedrock AgentCore

  • Build agents: OfferedHarness managed agent loop⁠Source 1
  • Host and run agents: OfferedAgentCore Runtime⁠Source 1
  • Identity and access: OfferedAgentCore Identity workload identities⁠Source 9
  • Registry and governance: OfferedAWS Agent Registry with approvals⁠Source 8
  • Traffic between agents, tools, and models: OfferedAgentCore Gateway⁠Source 15
  • Agents across organizations: OfferedRegistry shared through AWS RAM⁠Source 16

Microsoft Agent 365

  • Build agents: Not includedUse your chosen framework⁠Source 3
  • Host and run agents: Not includedYou host your agent⁠Source 4
  • Identity and access: OfferedEntra Agent ID⁠Source 7
  • Registry and governance: OfferedAgent registry in admin center⁠Source 12
  • Traffic between agents, tools, and models: PreviewTooling Gateway for MCP servers⁠Source 17
  • Agents across organizations: Not publicly documented

At a glance

TopicAmazon Bedrock AgentCoreMicrosoft Agent 365
Builds and hosts agentsBuild agents with Harness or the AgentCore SDK; serverless AgentCore Runtime hosts them.⁠Source 1, Source 14Microsoft says the Agent 365 SDK doesn’t build, host, deploy, or execute the agent.⁠Source 4
Where governed agents runIn AgentCore Runtime, or elsewhere: AWS says the Registry can list agents on other providers or on premises, and Identity covers self-hosted agents.⁠Source 1, Source 14, Source 18Wherever the agent already runs, such as Azure, AWS, Google Cloud, or on premises.⁠Source 4 Premium capabilities may vary by agent type and platform.⁠Source 6
Agent identityWorkload identities in AgentCore Identity; inbound calls can carry JWTs from any OAuth 2.0 provider, such as Microsoft Entra ID or Okta.⁠Source 9, Source 14, Source 19Agent identities live in Microsoft Entra Agent ID; the inventory also lists agents without one.⁠Source 7, Source 20
Pricing modelBy use, billed per service, with no upfront commitment or minimum fee.⁠Source 5Lists at $15 per user per month, or in Microsoft 365 E7.⁠Source 6 Basic identity and inventory come with Microsoft Cloud subscriptions; enterprise customers need Microsoft 365 E5, or E3 with the Defender and Purview suites.⁠Source 6
Generally availableSince October 2025; AWS Agent Registry since August 2026.⁠Source 21Since 1 May 2026, for the Commercial segment.⁠Source 22

What each one is

Amazon Bedrock AgentCore

Amazon Bedrock AgentCore is AWS’s platform for building, deploying, and operating agents with any framework and foundation model.⁠Source 1 Its modular services, usable together or independently, include Runtime to host agents, Identity, Gateway and Policy to control tool access, Observability, and AWS Agent Registry.⁠Source 1, Source 8, Source 9, Source 10, Source 23

Microsoft Agent 365

Microsoft Agent 365 is a Microsoft 365 service that provides a centralized control plane to discover, manage, govern, and secure AI agents.⁠Source 2 Microsoft splits the work: Agent 365 inventories agents, and Microsoft Entra Agent ID handles identities, permissions, and protections.⁠Source 24

The differences that matter

  1. How far each registry reaches

    Amazon Bedrock AgentCore

    AWS Agent Registry can list agents and MCP servers on AWS, on premises, or in other clouds; it currently auto-detects only AgentCore Runtimes and Gateways.⁠Source 1, Source 11

    Microsoft Agent 365

    The Agent 365 registry covers Microsoft and non-Microsoft agents; agents built outside Microsoft 365 channels and Entra Agent ID need extra steps to appear.⁠Source 12, Source 20, Source 25

    AI agents can search AWS Agent Registry through its MCP endpoint.⁠Source 8 Whether agents can search the Agent 365 registry is not publicly documented.

  2. Where policy is enforced

    Amazon Bedrock AgentCore

    Policy can check each request through an AgentCore Gateway against rules, written in natural language or Cedar, before allowing tool access.⁠Source 10

    Microsoft Agent 365

    Admins use Entra Conditional Access on agent identities, policy templates from Entra, Purview, SharePoint, and Defender, and an organization-wide block.⁠Source 7, Source 26, Source 27

  3. Remote and partner agents

    Amazon Bedrock AgentCore

    A registry can be shared with AWS accounts outside your AWS Organization by invitation, and resource-based policies can open a Runtime agent to another account.⁠Source 16, Source 28

    Microsoft Agent 365

    A published agent can be added to a customer’s tenant through a multitenant blueprint; managing agents across tenants you administer is in preview.⁠Source 7, Source 29

    Microsoft says its separate Copilot Studio and Microsoft Foundry can provide built-in Agent 365 integration for some scenarios; their agents can call A2A agents hosted elsewhere.⁠Source 30, Source 31, Source 32, Source 33

For security teams

What a security review asks, answered from each vendor’s public documentation.

TopicAmazon Bedrock AgentCoreMicrosoft Agent 365
Network exposureGateway can forward requests to an agent’s endpoint URL; callers in a VPC can reach AgentCore over PrivateLink.⁠Source 15, Source 34Notifications (preview) need a messaging endpoint Agent 365 sends to.⁠Source 35 Agent 365’s private networking is not publicly documented.
IdentityAgent identities are workload identities in AgentCore Identity; its inbound authorizer accepts JWTs from any OAuth 2.0 identity provider.⁠Source 9, Source 19Agent identities are Entra service principals, managed with Conditional Access and consent; the inventory also lists agents without one.⁠Source 7, Source 20
Access changes and revocationExplicit deny policies can block Runtime, Gateway, and Memory access; removing an account from a registry share revokes its access.⁠Source 16, Source 28Block an agent organization-wide (only in Copilot Chat for SharePoint and Foundry agents), or disable an Entra blueprint’s agents.⁠Source 7, Source 27
Audit trailCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls; Policy logs its decisions.⁠Source 10, Source 11, Source 36, Source 37Purview audit logs of agent activities need E7 or an Agent 365 license.⁠Source 2 Observability data is kept 30 days.⁠Source 13
ComplianceHIPAA eligible; AWS lists it as FedRAMP (Class C and Class D), SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 38, Source 39Microsoft says it meets FedRAMP High controls its assessor reviewed, with authorization pending (announced).⁠Source 2 Not yet a Core Online Service.⁠Source 13

Full comparison

18 criteria in five groups. Every cell links to its source, or says no public source answers it.

Amazon Bedrock AgentCore and Microsoft Agent 365 compared on 18 criteria
Amazon Bedrock AgentCoreMicrosoft Agent 365
What it is
What it is and who it’s forAWS platform to build, deploy, and operate agents with any framework and foundation model, as modular services used together or independently.⁠Source 1Microsoft 365 service providing a centralized control plane to discover, manage, govern, and secure AI agents, aimed at IT and security leaders.⁠Source 2, Source 25
MaturityGenerally available since October 2025; AWS Agent Registry since August 2026.⁠Source 21 Support for the Registry’s preview namespace ends on 30 October 2026.⁠Source 11Generally available since 1 May 2026 for the Commercial segment.⁠Source 22 Registry sync and multi-tenant management are in preview.⁠Source 29, Source 30
Control
Agent registry and discoveryAWS Agent Registry catalogs agents, MCP servers, tools, and skills on AWS, on premises, or in other clouds, behind an approval workflow.⁠Source 1, Source 8An agent registry in the Microsoft 365 admin center lists Microsoft and non-Microsoft agents, including agents without an Entra agent identity.⁠Source 12, Source 20
Identity and access controlAgent identities are workload identities in AgentCore Identity.⁠Source 9 Calls to Runtime agents use IAM SigV4 by default, or JWTs from any OAuth 2.0 identity provider.⁠Source 19, Source 40Agent identities live in Microsoft Entra Agent ID, managed with Conditional Access, permission grants, and consent.⁠Source 7 The inventory also lists agents without one.⁠Source 20
Ownership, policy, and revocationPolicy can check Gateway traffic against rules on which tools agents may call, in natural language or Cedar.⁠Source 10 An owner field is not publicly documented.Each Entra agent identity needs a sponsor.⁠Source 7 Admins can block agents organization-wide, apply policy templates, and review agents without owners.⁠Source 12, Source 26, Source 27
Audit log and observabilityCloudTrail can log Gateway calls (data events are off by default) and logs Registry control-plane calls.⁠Source 11, Source 36, Source 37 Telemetry is OpenTelemetry-compatible, in CloudWatch.⁠Source 23Purview audit logs and eDiscovery of agent activities need E7 or Agent 365; not in GCC.⁠Source 2 Observability data appears in Defender and Purview, kept 30 days.⁠Source 3, Source 13
Connection
How agents connectAgents can deploy to serverless AgentCore Runtime, or a Gateway can forward requests to an agent’s endpoint URL.⁠Source 1, Source 15The SDK works with agents on Azure, AWS, Google Cloud, or on premises.⁠Source 3 Notifications, in preview, need a messaging endpoint URL that Agent 365 sends to.⁠Source 35
Agents across organizationsAWS RAM shares a registry with AWS accounts, by invitation outside your AWS Organization.⁠Source 16 Resource-based policies can open a Runtime agent to another account.⁠Source 28A published agent can join a customer’s tenant through a multitenant blueprint.⁠Source 7 Agents in Microsoft’s separate Foundry and Copilot Studio can call A2A agents.⁠Source 32, Source 33
Protocol supportRuntime agents can serve HTTP, MCP, A2A, or AG-UI.⁠Source 41 Gateway acts as one MCP server over its MCP targets; Registry checks records against MCP and A2A schemas.⁠Source 11, Source 42Tenant-wide control of agents’ tools, including Microsoft MCP servers; your own in preview.⁠Source 2, Source 17 Microsoft’s separate Foundry and Copilot Studio agents can use A2A.⁠Source 32, Source 33
Frameworks, models, and clouds supportedRuntime takes custom or open-source frameworks, such as CrewAI, LangGraph, and Strands Agents.⁠Source 1 Registry and Identity work with agents outside Runtime.⁠Source 14, Source 18Works with Microsoft and third-party agents.⁠Source 2 SDK docs name LangChain, CrewAI, LlamaIndex, and the OpenAI Agents SDK; agents keep their own host.⁠Source 4, Source 30
Operations
Deployment options and data residencyAWS says cross-region inference can move Memory, Policy, and Evaluations prompts out of the primary Region; AgentCore may store content to improve your service.⁠Source 1, Source 43A Microsoft 365 service that honors the EU Data Boundary and doesn’t currently support Advanced Data Residency.⁠Source 2, Source 13 Self-hosting it is not publicly documented.
Compliance attestationsAWS lists AgentCore as FedRAMP (Class C and Class D) compliant.⁠Source 38, Source 39 It is HIPAA eligible, and SOC 2, ISO 27001:2022, and CSA STAR compliant.⁠Source 21, Source 38Microsoft says Agent 365 meets all FedRAMP High controls its assessor reviewed, with authorization pending (announced).⁠Source 2 Not yet a Core Online Service.⁠Source 13
Support and SLAAWS says the Amazon Bedrock SLA applies to AgentCore.⁠Source 14 Basic Support is included for all AWS customers.⁠Source 44No specific SLA for the Frontier preview program.⁠Source 45 An SLA or support plan specific to the generally available service is not publicly documented.
Time and effort to get runningAn AWS account with credentials, plus IAM permissions for AgentCore calls and CDK deployment.⁠Source 46 The AgentCore CLI is an npm package needing Node.js 20 or later.⁠Source 46Enterprise customers need Microsoft 365 E5, or E3 with Defender Suite and Purview Suite, and at least one user with an Agent 365 license.⁠Source 6, Source 22
Pricing model and public pricesBy use, billed per service, with no upfront commitment or minimum fee.⁠Source 5 Registry has a monthly free tier; Runtime v1 CPU is $0.0895 per vCPU-hour.⁠Source 5Per user, not per agent: lists at $15 a month standalone, or in Microsoft 365 E7.⁠Source 6 Microsoft Cloud subscribers get foundational capabilities at no extra cost.⁠Source 6
Building
Agent building toolsHarness defines an agent from a model, system prompt, and tools in one API call, or you write the loop with Strands, LangGraph, Google ADK, or others.⁠Source 1, Source 46Microsoft says the Agent 365 SDK isn’t an agent-building framework.⁠Source 3 For low-code building, its docs point to Microsoft’s separate Copilot Studio.⁠Source 47
Model accessModel-agnostic: AWS names OpenAI, Google Gemini, Anthropic Claude, Amazon Nova, Meta Llama, and Mistral models, in or outside Amazon Bedrock.⁠Source 14Microsoft says the SDK doesn’t call or select models; the agent keeps making its own model calls.⁠Source 3, Source 4
Integrations and ecosystemGateway has 1-click integrations with tools such as Salesforce, Slack, Jira, Asana, and Zendesk, and can import partner tools bought through AWS Marketplace.⁠Source 14, Source 48Microsoft says it launched with partner agents and agent factories, such as Zendesk and n8n.⁠Source 49, Source 50 Work IQ MCP tools for Mail, Teams, and more are in preview.⁠Source 51

Which to choose

Choose Amazon Bedrock AgentCore if

  • You want to build, deploy, and operate agents on one AWS platform, with frameworks such as LangGraph, CrewAI, or Strands Agents.⁠Source 1
  • You want per-request policy at a gateway, written in natural language or Cedar, on which tools each agent may call.⁠Source 10
  • You want pay-per-use pricing for each service, with no upfront commitment or minimum fee.⁠Source 5
  • Your company uses AWS Organizations and wants one shared registry, with AgentCore Runtimes and Gateways in member accounts auto-detected once enabled.⁠Source 11, Source 16

Choose Microsoft Agent 365 if

  • You build agents in Microsoft’s separate Copilot Studio or Foundry, which Microsoft says can provide built-in Agent 365 integration for some scenarios.⁠Source 30, Source 31
  • You want agent identities in Microsoft Entra, under the same Conditional Access, consent, and lifecycle controls as the rest of your tenant.⁠Source 7
  • You want named accountability: each Entra agent identity needs a sponsor, and admins can block or delete agents without owners.⁠Source 7, Source 12
  • You’d rather license per user than per agent: one Agent 365 license covers all of a user’s agents.⁠Source 6

Questions buyers ask

Can Microsoft Agent 365 manage agents on Amazon Bedrock AgentCore?

Registry sync, in preview, can import Amazon Bedrock AgentCore agents into Agent 365’s registry, and the Agent 365 SDK works with agents hosted on AWS.⁠Source 3, Source 52 In this preview, the connection uses an AWS access key, and an admin starts each sync manually.⁠Source 52, Source 53

How is each one priced?

AgentCore bills each service by use, with no upfront commitment, and the Registry has a monthly free tier.⁠Source 5 Agent 365 lists at $15 per user per month standalone, or comes in Microsoft 365 E7.⁠Source 6 Microsoft Cloud subscribers get foundational capabilities at no extra cost.⁠Source 6

Do they support MCP and A2A?

AgentCore Runtime can host MCP and A2A servers.⁠Source 41 Agent 365 can control agents’ tool access, including Microsoft MCP servers; registering your own is in preview.⁠Source 2, Source 17 Microsoft documents A2A for its separate Foundry and Copilot Studio.⁠Source 32, Source 33 For Agent 365 itself, A2A is not publicly documented.

Does AgentCore work with Microsoft Entra ID?

AWS says AgentCore Identity’s authorizer can use existing identity providers such as Microsoft Entra ID, Okta, or Amazon Cognito, and works with any OAuth 2.0 provider.⁠Source 14, Source 19 Agent 365’s agent identities live in Microsoft Entra Agent ID.⁠Source 7

How we compare

Read the full method

Every claim on this page links to a public source. Where none answers a question, the page says so.

We re-check every fact at least every 90 days. This page was last checked .

Something wrong or out of date? Tell us and we’ll correct it.

Sources

60 public sources, each with the date we checked it. Every one opens in a new tab.

  1. Source 1: Overview - Amazon Bedrock AgentCore (Developer Guide) AWS · checked Back:abcdefghijklmnop

  2. Source 2: Microsoft Agent 365 - Service Descriptions | Microsoft Learn Microsoft · checked Back:abcdefghijkl

  3. Source 3: Agent 365 SDK frequently asked questions | Microsoft Learn Microsoft · checked Back:abcdefgh

  4. Source 4: Microsoft Agent 365 SDK overview | Microsoft Learn Microsoft · checked Back:abcdefg

  5. Source 5: Amazon Bedrock AgentCore Pricing AWS · checked Back:abcdef

  6. Source 6: Licensing Documents Microsoft · checked Back:abcdefghij

  7. Source 7: Agent 365 identity | Microsoft Learn Microsoft · checked Back:abcdefghijklmn

  8. Source 8: AWS Agent Registry: Discover and manage agents, tools, and resources AWS · checked Back:abcde

  9. Source 9: Provide identity and credential management for agent applications with Amazon Bedrock AgentCore Identity AWS · checked Back:abcdef

  10. Source 10: Policy in Amazon Bedrock AgentCore: Control Agent Interactions AWS · checked Back:abcdef

  11. Source 11: Key capabilities - AWS Agent Registry AWS · checked Back:abcdefg

  12. Source 12: Agent Registry in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abcdef

  13. Source 13: Data handling, data residency, and compliance in Agent 365 observability | Microsoft Learn Microsoft · checked Back:abcdef

  14. Source 14: Amazon Bedrock AgentCore FAQs AWS · checked Back:abcdefghi

  15. Source 15: HTTP passthrough targets - AgentCore Gateway AWS · checked Back:abc

  16. Source 16: Sharing a registry across accounts with AWS RAM AWS · checked Back:abcde

  17. Source 17: Bring your own (BYO) MCP server in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abc

  18. Source 18: Features of AgentCore Identity AWS · checked Back:ab

  19. Source 19: Configure inbound JWT authorizer AWS · checked Back:abcd

  20. Source 20: Agent Registry convergence with Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back:abcde

  21. Source 21: Release notes - Amazon Bedrock AgentCore AWS · checked Back:abc

  22. Source 22: Microsoft Agent 365 overview | Microsoft Learn Microsoft · checked Back:abc

  23. Source 23: Observe your agent applications on Amazon Bedrock AgentCore Observability AWS · checked Back:ab

  24. Source 24: Protect agent identities with Microsoft Entra | Microsoft Learn Microsoft · checked Back to text

  25. Source 25: Microsoft Agent 365: The Control Plane for Agents Microsoft · checked Back:ab

  26. Source 26: Policy templates | Microsoft Learn Microsoft · checked Back:ab

  27. Source 27: Governance and Lifecycle actions for agents available in Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:abc

  28. Source 28: Resource-based policies for Amazon Bedrock AgentCore AWS · checked Back:abc

  29. Source 29: Manage agents across multiple tenants in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn Microsoft · checked Back:ab

  30. Source 30: Choose an Agent 365 Integration Option | Microsoft Learn Microsoft · checked Back:abcde

  31. Source 31: What is Microsoft Foundry? - Microsoft Foundry | Microsoft Learn Microsoft · checked Back:ab

  32. Source 32: Connect to an agent over the Agent2Agent (A2A) protocol - Microsoft Copilot Studio | Microsoft Learn Microsoft · checked Back:abcd

  33. Source 33: Connect to an A2A agent endpoint from Foundry Agent Service - Microsoft Foundry | Microsoft Learn Microsoft · checked Back:abcd

  34. Source 34: Use interface VPC endpoints (AWS PrivateLink) with Amazon Bedrock AgentCore AWS · checked Back to text

  35. Source 35: Agent Messaging Endpoint | Microsoft Learn Microsoft · checked Back:ab

  36. Source 36: Log Amazon Bedrock AgentCore Gateway API calls with CloudTrail AWS · checked Back:ab

  37. Source 37: Enable CloudTrail data event logging for Amazon Bedrock AgentCore Gateway resources - Amazon Bedrock AgentCore AWS · checked Back:ab

  38. Source 38: Compliance validation for Amazon Bedrock AgentCore AWS · checked Back:abc

  39. Source 39: Federal Risk and Authorization Management Program (FedRAMP) - Services in Scope - Amazon Web Services AWS · checked Back:ab

  40. Source 40: Authenticate and authorize with Inbound Auth and Outbound Auth AWS · checked Back to text

  41. Source 41: Understand the AgentCore Runtime service contract AWS · checked Back:ab

  42. Source 42: Supported targets for Amazon Bedrock AgentCore gateways AWS · checked Back to text

  43. Source 43: Cross-region inference in AgentCore Memory, Policy in AgentCore, and AgentCore Evaluations AWS · checked Back to text

  44. Source 44: Compare AWS Support plans AWS · checked Back to text

  45. Source 45: Preview Agent 365 features through the Frontier program | Microsoft Learn Microsoft · checked Back to text

  46. Source 46: Get started with Amazon Bedrock AgentCore AWS · checked Back:abc

  47. Source 47: Get started with Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back to text

  48. Source 48: Amazon Bedrock AgentCore Gateway: A secure AI gateway for agents, tools, and models AWS · checked Back to text

  49. Source 49: Ecosystem partner agents available in Agent 365 | Microsoft Learn Microsoft · checked Back to text

  50. Source 50: Microsoft Agent 365, now generally available, expands capabilities and integrations | Microsoft Security Blog Microsoft · checked Back to text

  51. Source 51: Connect existing agents to Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back to text

  52. Source 52: Connect Amazon Bedrock to Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back:abcd

  53. Source 53: Connected platforms in Microsoft Agent 365 | Microsoft Learn Microsoft · checked Back to text

  54. Source 54: Why Blocks? Blocks.ai · checked Back to text

  55. Source 55: What is Blocks? Blocks.ai · checked Back to text

  56. Source 56: Your company's private network Blocks.ai · checked Back to text

  57. Source 57: Network requirements Blocks.ai · checked Back to text

  58. Source 58: Solutions: Agent sprawl Blocks.ai · checked Back to text

  59. Source 59: Solutions: Partner networks Blocks.ai · checked Back to text

  60. Source 60: Pricing Blocks.ai · checked Back to text